CVE-2026-66006
- EPSS 0.32%
- Veröffentlicht 24.07.2026 14:57:50
- Zuletzt bearbeitet 30.07.2026 15:45:04
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup comp...
CVE-2026-26187
- EPSS 0.39%
- Veröffentlicht 13.02.2026 18:34:10
- Zuletzt bearbeitet 18.02.2026 21:32:15
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage bound...
CVE-2025-68671
- EPSS 0.25%
- Veröffentlicht 15.01.2026 22:35:44
- Zuletzt bearbeitet 25.02.2026 15:03:23
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed r...