blob: 9a706ff1b4d2bdbc37ff79c1175d5be377d172bb [file] [log] [blame]
id: GO-2024-2477
modules:
- module: github.com/openfga/openfga
versions:
- fixed: 1.4.3
vulnerable_at: 1.4.2
summary: OpenFGA denial of service in github.com/openfga/openfga
cves:
- CVE-2024-23820
ghsas:
- GHSA-rxpw-85vw-fx87
references:
- advisory: https://github.com/openfga/openfga/security/advisories/GHSA-rxpw-85vw-fx87
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-23820
- fix: https://github.com/openfga/openfga/commit/908ac85c8b7769c8042cca31886df8db01976c39
- web: https://github.com/openfga/openfga/releases/tag/v1.4.3
source:
id: GHSA-rxpw-85vw-fx87
created: 2024-06-14T11:36:36.858461-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE