Missing Authentication Vulnerability in lakeFS by Treeverse
CVE-2025-64179

5.3MEDIUM

Key Information:

Vendor

Treeverse

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2025-64179?

The lakeFS tool developed by Treeverse, which enables transformation of object storage into Git-like repositories, has a security vulnerability in its versions prior to 1.71.0. The /api/v1/usage-report/summary endpoint lacks proper authentication, allowing unauthorized users to access aggregate API usage counts. While the vulnerability does not expose sensitive information, it could reveal valuable insights concerning service utilization and availability. For those still using earlier versions, it is advisable to implement a load balancer or an application-level firewall to restrict access to this endpoint as a temporary mitigation measure.

Affected Version(s)

lakeFS < 1.71.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64179 : Missing Authentication Vulnerability in lakeFS by Treeverse