OpenFGA DoS vulnerability
Description
Published by the National Vulnerability Database
Oct 17, 2023
Published to the GitHub Advisory Database
Oct 18, 2023
Reviewed
Oct 18, 2023
Last updated
Nov 12, 2023
Overview
OpenFGA is vulnerable to a DoS attack. When a number of ListObjects calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and the service as a whole becomes unresponsive.
Fix
Upgrade to v1.3.4. This upgrade is backwards compatible.
References