VDB
Sign up
HIGH

GHSA-28q9-9c3g-v3f9

lakeFS vulnerable to authenticated users deleting files they are not authorized to delete

Quick fix

GHSA-28q9-9c3g-v3f9 — github.com/treeverse/lakefs: upgrade to the fixed version with the command below.

go get github.com/treeverse/lakefs@v0.82.0

Details

### Impact

Authenticated users can send a request to delete-objects through the s3 gateway and delete files they are not authorized to delete.

### Patches

lakeFS v0.82.0 and later

### Workarounds

Drop specific request to the lakeFS listen port. Any request with "Authorization" header and value that starts with "AWS".

### References

[advisories/GHSA-28q9-9c3g-v3f9](https://github.com/treeverse/lakeFS/security/advisories/GHSA-28q9-9c3g-v3f9)

### For more information If you have any questions or comments about this advisory:

Ask on the [lakeFS Slack](https://github.com/treeverse/lakeFS/security/advisories/lakefs.io/slack) #help channel Email us at [security@treeverse.io](mailto:security@treeverse.io)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/treeverse/lakefs
Introduced in: 0Fixed in: 0.82.0
Fixgo get github.com/treeverse/lakefs@v0.82.0

References