CVE Details
Basic Information
| Title | CVE-2025-48371 |
|---|---|
| Type | cve |
| Published | 2025-05-22T23:15:19 |
| Last Seen | 2025-05-22T23:23:18 |
CVSS Information
| Base Score | 0.0 () |
|---|---|
| Attack Vector | |
| Attack Complexity | |
| Privileges Required | |
| User Interaction | |
| Scope | |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | OpenFGA versions 1.8.0 through 1.8.12 are vulnerable to an authorization bypass, allowing attackers to access resources without proper permissions. This vulnerability could lead to unauthorized access and potential data breaches. |
|---|---|
| AI Severity | Medium |
| Vendor | OpenFGA Community |
| Product | OpenFGA |
| Affected Version | 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.8.6, 1.8.7, 1.8.8, 1.8.9, 1.8.10, 1.8.11, 1.8.12 |
Additional Information
| CVE List | CVE-2025-48371 |
|---|---|
| CWE List | CWE-285 |
| Bulletin Family | cve |
Description
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass…
CVSS Score Summary
Base Score: %!f(string=#) ()