Логотип exploitDog
bind:CVE-2025-68671
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-68671

Количество 2

Количество 2

nvd логотип

CVE-2025-68671

25 дней назад

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire. This vulnerability is fixed in 1.75.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f2ph-gc9m-q55f

25 дней назад

lakeFS is Missing Timestamp Validation in S3 Gateway Authentication

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-68671

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire. This vulnerability is fixed in 1.75.0.

CVSS3: 6.5
0%
Низкий
25 дней назад
github логотип
GHSA-f2ph-gc9m-q55f

lakeFS is Missing Timestamp Validation in S3 Gateway Authentication

CVSS3: 6.5
0%
Низкий
25 дней назад

Уязвимостей на страницу