Technologyglobalverified · 90%

OpenFGA Improper Policy Enforcement

When
Where
Global (internet)
Category
cyber_advisory · go

## Description In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response. ## Preconditions This applies if the following preconditions are met: 1. You run OpenFGA with MySQL as the datastore 2. Your authorization decisions rely on case-sensitive user strings. ## Fix Upgrade to OpenFGA 1.18.0 or greater. ## Acknowledgements OpenFGA would like to thank @sahajamoth for the detailed report.

Sources

Defaxon links out to the original reporting and never republishes article text.

Correlated events

Computed by the Defaxon correlation engine — linked by shared actors, co-location, and temporal proximity. Scored hypotheses, never causal claims.

No correlated events found in the current window. As more events arrive, connections form automatically.

← Back to the live map