CVE-2024-42473
Estado: AnalizadaCrítica (9.8)—
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-42473",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-42473",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-10T14:18:27.056147Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "openfga",
"product": "openfga",
"versions": [
{
"status": "affected",
"version": ">=1.5.7, <= 1.5.8"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*"
],
"vendor": "openfga",
"product": "openfga",
"versions": [
{
"status": "affected",
"version": "1.5.7",
"versionType": "custom",
"lessThanOrEqual": "1.5.8"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-08-12T13:38:35.680",
"references": [
{
"url": "https://github.com/openfga/openfga/security/advisories/GHSA-3f6g-m4hr-59h8",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release."
},
{
"lang": "es",
"value": "OpenFGA es un motor de autorización/permiso. OpenFGA v1.5.7 y v1.5.8 son vulnerables a la omisión de autorización al llamar a Check API con un modelo que usa expresiones \"pero no\" y \"de\" y un conjunto de usuarios. Los usuarios deben cambiar a la versión 1.5.6 lo antes posible. Esta degradación es compatible con versiones anteriores. Al momento de la publicación, no hay ningún parche disponible, pero los encargados de mantenimiento de OpenFGA están planeando incluirlo en una versión futura."
}
],
"lastModified": "2026-06-17T07:49:31.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openfga:openfga:1.5.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77BDB561-C7A1-4E86-8A04-E71EB42F3A74"
},
{
"criteria": "cpe:2.3:a:openfga:openfga:1.5.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76C9D905-62B8-49FD-9B7D-73C0E880D0FD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}