Логотип exploitDog
bind:CVE-2025-68671
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-68671

Количество 2

Количество 2

nvd логотип

CVE-2025-68671

24 дня назад

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire. This vulnerability is fixed in 1.75.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f2ph-gc9m-q55f

24 дня назад

lakeFS is Missing Timestamp Validation in S3 Gateway Authentication

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-68671

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire. This vulnerability is fixed in 1.75.0.

CVSS3: 6.5
0%
Низкий
24 дня назад
github логотип
GHSA-f2ph-gc9m-q55f

lakeFS is Missing Timestamp Validation in S3 Gateway Authentication

CVSS3: 6.5
0%
Низкий
24 дня назад

Уязвимостей на страницу