{"id":"GHSA-28q9-9c3g-v3f9","aliases":["GO-2022-1019"],"url":"https://o3.security/vulnerability/GHSA-28q9-9c3g-v3f9","summary":"lakeFS vulnerable to authenticated users deleting files they are not authorized to delete","details":"### Impact\n\nAuthenticated users can send a request to delete-objects through the s3 gateway and delete files they are not authorized to delete.\n\n### Patches\n\nlakeFS v0.82.0 and later\n\n### Workarounds\n\nDrop specific request to the lakeFS listen port. Any request with \"Authorization\" header and value that starts with \"AWS\".\n\n### References\n\n[advisories/GHSA-28q9-9c3g-v3f9](https://github.com/treeverse/lakeFS/security/advisories/GHSA-28q9-9c3g-v3f9)\n\n### For more information\nIf you have any questions or comments about this advisory:\n\nAsk on the [lakeFS Slack](https://github.com/treeverse/lakeFS/security/advisories/lakefs.io/slack) #help channel\nEmail us at [security@treeverse.io](mailto:security@treeverse.io)","published":"2022-09-23T15:13:14Z","modified":"2024-08-21T16:28:58.664990Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/treeverse/lakefs","fixedVersion":"0.82.0"}],"fix":{"url":"https://github.com/treeverse/lakeFS/commit/81182bf9c0cf57f3cec3c893cf739b2069305e37","label":"treeverse/lakeFS@81182bf"},"references":[{"type":"WEB","url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-28q9-9c3g-v3f9"},{"type":"WEB","url":"https://github.com/treeverse/lakeFS/commit/81182bf9c0cf57f3cec3c893cf739b2069305e37"},{"type":"PACKAGE","url":"https://github.com/treeverse/lakeFS"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-21T16:28:58.664990Z"}}