VDB
Sign up
—

GO-2023-2012

lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs

Quick fix

GO-2023-2012 — github.com/treeverse/lakefs: upgrade to the fixed version with the command below.

go get github.com/treeverse/lakefs@v0.106.0

Details

lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/treeverse/lakefs
Introduced in: 0Fixed in: 0.106.0
Fixgo get github.com/treeverse/lakefs@v0.106.0

References