CVE-2024-23820

CVSS V2 None CVSS V3 None
Description
OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an `out of memory` error and terminate. Version 1.4.3 contains a patch for this issue.
Overview
  • CVE ID
  • CVE-2024-23820
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-26T16:37:27.065Z
  • Last Modified Date
  • 2024-01-26T16:37:27.065Z
History
Created Old Value New Value Data Type Notes
2024-06-26 07:06:53 Added to TrackCVE