PT-2025-45013 · Lakefs · Lakefs
Published
2025-11-03
·
Updated
2025-11-17
·
CVE-2025-64179
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
lakeFS versions prior to 1.71.0
Description
lakeFS is a tool that transforms object storage into Git-like repositories. Versions 1.69.0 and below lack authentication for the
/api/v1/usage-report/summary endpoint, allowing unauthorized access to aggregate API usage counts. This does not disclose sensitive data but may reveal information about service activity or uptime. The vulnerable endpoint is /api/v1/usage-report/summary.Recommendations
Versions prior to 1.71.0 should be updated to version 1.71.0 or later.
As a workaround, block the request route
/api/v1/usage-report/summary using a load-balancer or application level firewall.Exploit
Fix
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lakefs