Upstream information
Description
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that user will inherit all of the previous user's credentials. This issue has been addressed in release version 1.33.0 and all users are advised to upgrade. The only known workaround for those who cannot upgrade is to not reuse usernames.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
CNA (GitHub) | |
---|---|
Base Score | 5.7 |
Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | High |
User Interaction | Required |
Scope | Unchanged |
Confidentiality Impact | Low |
Integrity Impact | High |
Availability Impact | Low |
CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- openSUSE-SU-2024:14567-1, published Thu Dec 12 18:51:05 2024
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
Container suse/sl-micro/6.0/baremetal-os-container:2.1.3-4.27 |
| |
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2024-14567 |
SUSE Timeline for this CVE
CVE page created: Wed Nov 27 00:00:50 2024CVE page last modified: Fri Dec 13 12:04:18 2024