Executive Summary

Informations
Name CVE-2023-35933 First vendor Publication 2023-06-26
Vendor Cve Last vendor Modification 2023-07-06

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 7.5
Base Score 7.5 Environmental Score 7.5
impact SubScore 3.6 Temporal Score 7.5
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vulnerable to a DoS attack when Check and ListObjects calls are executed against authorization models that contain circular relationship definitions. Users are affected by this vulnerability if they are using OpenFGA v1.1.0 or earlier, and if you are executing `Check` or `ListObjects` calls against a vulnerable authorization model. Users are advised to upgrade to version 1.1.1. There are no known workarounds for this vulnerability. Users that do not have circular relationships in their models are not affected.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35933

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Sources (Detail)

Source Url
MISC https://github.com/openfga/openfga/commit/087ce392595f3c319ab3028b5089118ea40...
https://github.com/openfga/openfga/security/advisories/GHSA-hr9r-8phq-5x8j
https://openfga.dev/api/service#/Relationship%20Queries/Check
https://openfga.dev/api/service#/Relationship%20Queries/ListObjects

Alert History

If you want to see full details history, please login or register.
0
1
2
Date Informations
2023-07-07 00:27:23
  • Multiple Updates
2023-06-27 05:27:20
  • Multiple Updates
2023-06-27 00:27:18
  • First insertion