PT-2026-3139 · Lakefs · Lakefs
Published
2026-01-15
·
Updated
2026-01-26
·
CVE-2025-68671
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
lakeFS versions prior to 1.75.0
Description
lakeFS's S3 gateway does not validate timestamps in authenticated requests, which allows for replay attacks. An attacker capturing a valid signed request can replay it until credentials are rotated, even after the request's intended expiration. The API endpoints are susceptible to this issue. The vulnerable parameters include those used in authenticated requests.
Recommendations
Upgrade to version 1.75.0.
Use short-lived credentials and rotate access keys frequently, deactivating old keys.
Restrict S3 gateway access to trusted networks/IPs.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lakefs