github.com/treeverse/lakefs is vulnerable to Authentication Bypass
53
Medium Risk
The POST /setup_comm_prefs endpoint is authentication-exempt and, unlike POST /setup_lakefs, performs no setup-state check. After an installation is initialized, an unauthenticated caller can POST to this endpoint to overwrite the stored operator communication preferences such as email, name, company, and feature or security update opt-ins. The same request fires a falsified telemetry event tagged with the legitimate installation ID and can silently opt the installation out of vendor security update communications. The fix gates the endpoint with 412 and 409 responses plus one-way latches so overwrites are rejected once preferences are captured.
You are affected if you are using a version that falls within the vulnerable range.
github.com/treeverse/lakefs is vulnerable to Authentication Bypass in versions 0.105.0 - 1.84.0.
Upgrade the github.com/treeverse/lakefs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant