-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from missing authorization interceptors on streaming endpoints. The patch added streaming interceptors in both service configuration (service.go) and server setup (server.go). The original vulnerable versions lacked these interceptors, leaving streaming endpoints like 'streamed-list-objects' unprotected. The functions responsible for configuring interceptors (BuildService and Server.Run) were modified in the fix to include streaming interceptors, confirming their role in the vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/openfga/openfga | go | <= 0.2.3 | 0.2.4 |
Ongoing coverage of React2Shell