blob: a35aa49ca85045d39d54d58bdb39b0900bed1c5d [file] [log] [blame] [edit]
id: GO-2026-4321
modules:
- module: github.com/treeverse/lakefs
versions:
- fixed: 1.75.0
vulnerable_at: 1.74.4
summary: lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs
cves:
- CVE-2025-68671
ghsas:
- GHSA-f2ph-gc9m-q55f
references:
- advisory: https://github.com/treeverse/lakeFS/security/advisories/GHSA-f2ph-gc9m-q55f
- web: https://github.com/treeverse/lakeFS/commit/92966ae611d7f1a2bbe7fd56f9568c975aab2bd8
- web: https://github.com/treeverse/lakeFS/issues/9599
- web: https://github.com/treeverse/lakeFS/pull/9710
source:
id: GHSA-f2ph-gc9m-q55f
created: 2026-01-16T00:25:29.610845193-05:00
review_status: UNREVIEWED