OpenFGA denial of service
Description
Published by the National Vulnerability Database
Jan 26, 2024
Published to the GitHub Advisory Database
Jan 26, 2024
Reviewed
Jan 26, 2024
Last updated
Feb 1, 2024
Overview
OpenFGA is vulnerable to a DoS attack. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an "out of memory" error and terminate.
Fix
Upgrade to v1.4.3. This upgrade is backwards compatible.
References