{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-29T12:37:05.695","vulnerabilities":[{"cve":{"id":"CVE-2024-42473","sourceIdentifier":"security-advisories@github.com","published":"2024-08-12T13:38:35.680","lastModified":"2026-06-17T07:49:31.137","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release."},{"lang":"es","value":"OpenFGA es un motor de autorización/permiso. OpenFGA v1.5.7 y v1.5.8 son vulnerables a la omisión de autorización al llamar a Check API con un modelo que usa expresiones \"pero no\" y \"de\" y un conjunto de usuarios. Los usuarios deben cambiar a la versión 1.5.6 lo antes posible. Esta degradación es compatible con versiones anteriores. Al momento de la publicación, no hay ningún parche disponible, pero los encargados de mantenimiento de OpenFGA están planeando incluirlo en una versión futura."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"openfga","product":"openfga","versions":[{"version":">=1.5.7, <= 1.5.8","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"openfga","product":"openfga","defaultStatus":"unknown","cpes":["cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.5.7","lessThanOrEqual":"1.5.8","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-10T14:18:27.056147Z","id":"CVE-2024-42473","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openfga:openfga:1.5.7:*:*:*:*:*:*:*","matchCriteriaId":"77BDB561-C7A1-4E86-8A04-E71EB42F3A74"},{"vulnerable":true,"criteria":"cpe:2.3:a:openfga:openfga:1.5.8:*:*:*:*:*:*:*","matchCriteriaId":"76C9D905-62B8-49FD-9B7D-73C0E880D0FD"}]}]}],"references":[{"url":"https://github.com/openfga/openfga/security/advisories/GHSA-3f6g-m4hr-59h8","source":"security-advisories@github.com","tags":["Third Party Advisory"]}]}}]}