logo

Database

Insufficient data authenticity validation In github.com/openfga/openfga

Description

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

Description

In OpenFGA, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request.

Preconditions

This applies if the following preconditions are present:

    FGA runs with SharedIteratorCache enabled,

    FGA runs with ListObjectsIteratorCache enabled.

Fix

Upgrade to version 1.16.0 or greater.

Acknowledgements

OpenFGA would like to thank @j4xT for the discovery and the detailed report.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-8P8AM – Vulnerability | Fluid Attacks Database