GHSA-28q9-9c3g-v3f9
lakeFS vulnerable to authenticated users deleting files they are not authorized to delete
Quick fix
GHSA-28q9-9c3g-v3f9 — github.com/treeverse/lakefs: upgrade to the fixed version with the command below.
go get github.com/treeverse/lakefs@v0.82.0Details
### Impact
Authenticated users can send a request to delete-objects through the s3 gateway and delete files they are not authorized to delete.
### Patches
lakeFS v0.82.0 and later
### Workarounds
Drop specific request to the lakeFS listen port. Any request with "Authorization" header and value that starts with "AWS".
### References
[advisories/GHSA-28q9-9c3g-v3f9](https://github.com/treeverse/lakeFS/security/advisories/GHSA-28q9-9c3g-v3f9)
### For more information If you have any questions or comments about this advisory:
Ask on the [lakeFS Slack](https://github.com/treeverse/lakeFS/security/advisories/lakefs.io/slack) #help channel Email us at [security@treeverse.io](mailto:security@treeverse.io)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.82.0go get github.com/treeverse/lakefs@v0.82.0