User with permission to write actions can impersonate another user when auth token is configured in environment variable
Modified: 8/21/2024
package
pkg:go/github.com/treeverse/lakefs
User with permission to write actions can impersonate another user when auth token is configured in environment variable
Modified: 8/21/2024
lakeFS vulnerable to authenticated users deleting files they are not authorized to delete
Modified: 8/21/2024
lakeFS logs S3 credentials in plain text
Modified: 8/21/2024
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access
Modified: 2/19/2026
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files
Modified: 8/21/2024
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication
Modified: 2/3/2026
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository
Modified: 6/4/2024
lakeFS affected by unauthenticated access to API usage metrics
Modified: 11/17/2025
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion
Modified: 11/27/2024
lakeFS allows an authenticated user to cause a crash by exhausting server memory
Modified: 3/3/2025
Improper Access Control in github.com/treeverse/lakefs
Modified: 8/21/2024
Improper Access Control in github.com/treeverse/lakefs
Modified: 3/3/2026
lakeFS vulnerable to authenticated users deleting files they are not authorized to delete in github.com/treeverse/lakefs
Modified: 3/3/2026
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs
Modified: 3/3/2026
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs
Modified: 3/3/2026
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs
Modified: 3/3/2026
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs
Modified: 3/3/2026
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs
Modified: 3/3/2026
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs
Modified: 3/3/2026
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs
Modified: 3/3/2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs
Modified: 3/3/2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs
Modified: 2/19/2026