Missing Authentication Vulnerability in lakeFS by Treeverse
CVE-2025-64179
5.3MEDIUM
What is CVE-2025-64179?
The lakeFS tool developed by Treeverse, which enables transformation of object storage into Git-like repositories, has a security vulnerability in its versions prior to 1.71.0. The /api/v1/usage-report/summary endpoint lacks proper authentication, allowing unauthorized users to access aggregate API usage counts. While the vulnerability does not expose sensitive information, it could reveal valuable insights concerning service utilization and availability. For those still using earlier versions, it is advisable to implement a load balancer or an application-level firewall to restrict access to this endpoint as a temporary mitigation measure.
Affected Version(s)
lakeFS < 1.71.0
