{"id":"GHSA-28q9-9c3g-v3f9","summary":"lakeFS vulnerable to authenticated users deleting files they are not authorized to delete","details":"### Impact\n\nAuthenticated users can send a request to delete-objects through the s3 gateway and delete files they are not authorized to delete.\n\n### Patches\n\nlakeFS v0.82.0 and later\n\n### Workarounds\n\nDrop specific request to the lakeFS listen port. Any request with \"Authorization\" header and value that starts with \"AWS\".\n\n### References\n\n[advisories/GHSA-28q9-9c3g-v3f9](https://github.com/treeverse/lakeFS/security/advisories/GHSA-28q9-9c3g-v3f9)\n\n### For more information\nIf you have any questions or comments about this advisory:\n\nAsk on the [lakeFS Slack](https://github.com/treeverse/lakeFS/security/advisories/lakefs.io/slack) #help channel\nEmail us at [security@treeverse.io](mailto:security@treeverse.io)","aliases":["GO-2022-1019"],"modified":"2024-08-21T16:28:58.664990Z","published":"2022-09-23T15:13:14Z","database_specific":{"github_reviewed_at":"2022-09-23T15:13:14Z","nvd_published_at":null,"cwe_ids":["CWE-281","CWE-284"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-28q9-9c3g-v3f9"},{"type":"WEB","url":"https://github.com/treeverse/lakeFS/commit/81182bf9c0cf57f3cec3c893cf739b2069305e37"},{"type":"PACKAGE","url":"https://github.com/treeverse/lakeFS"}],"affected":[{"package":{"name":"github.com/treeverse/lakefs","ecosystem":"Go","purl":"pkg:golang/github.com/treeverse/lakefs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.82.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-28q9-9c3g-v3f9/GHSA-28q9-9c3g-v3f9.json"}}],"schema_version":"1.9.0"}