Логотип exploitDog
bind:CVE-2025-64179
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64179

Количество 2

Количество 2

nvd логотип

CVE-2025-64179

3 месяца назад

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in the /api/v1/usage-report/summary endpoint allows anyone to retrieve aggregate API usage counts. While no sensitive data is disclosed, the endpoint may reveal information about service activity or uptime. This issue is fixed in version 1.71.0 . To workaround the vulnerability, use a load-balancer or application level firewall in order to block the request route /api/v1/usage-report/summary.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-h238-5mwf-8xw8

3 месяца назад

lakeFS affected by unauthenticated access to API usage metrics

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64179

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in the /api/v1/usage-report/summary endpoint allows anyone to retrieve aggregate API usage counts. While no sensitive data is disclosed, the endpoint may reveal information about service activity or uptime. This issue is fixed in version 1.71.0 . To workaround the vulnerability, use a load-balancer or application level firewall in order to block the request route /api/v1/usage-report/summary.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-h238-5mwf-8xw8

lakeFS affected by unauthenticated access to API usage metrics

CVSS3: 5.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу