—
GO-2023-2012
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs
Quick fix
GO-2023-2012 — github.com/treeverse/lakefs: upgrade to the fixed version with the command below.
go get github.com/treeverse/lakefs@v0.106.0Details
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/treeverse/lakefs
Introduced in:
0Fixed in: 0.106.0Fix
go get github.com/treeverse/lakefs@v0.106.0