blob: 073f6ce1a09694c4b0b729951c6d7461b7cea7d1 [file] [log] [blame]
id: GO-2024-2581
modules:
- module: github.com/treeverse/lakefs
versions:
- introduced: 0.90.0
- fixed: 1.12.1
vulnerable_at: 1.12.0
summary: |-
User with ci:ReadAction permissions and write permissions to one path in a
repository may copy objects from any path in the repository in github.com/treeverse/lakefs
ghsas:
- GHSA-fvv5-h29g-f6w5
references:
- advisory: https://github.com/treeverse/lakeFS/security/advisories/GHSA-fvv5-h29g-f6w5
- web: https://github.com/treeverse/lakeFS/commit/56556ee5406fc5425b9302cd08a8d412635fdcd7
source:
id: GHSA-fvv5-h29g-f6w5
created: 2024-05-17T16:15:01.346474-04:00
review_status: UNREVIEWED