CVE 6.5 MEDIUM

lakeFS is Missing Timestamp Validation in S3 Gateway Authentication_CVE-2025-68671

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire. This vulnerability is fixed in 1.75.0.

Basic Information

ID CVE-2025-68671
Source GitHub_M
Published Jan 15, 2026 at 22:35

Affected Product

Vendor treeverse
Product lakeFS
Version < 1.75.0
Affected Versions treeverse lakeFS < 1.75.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.