Junglewise Threat Intelligence

GO-2023-2397 - User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treev

Severity: info · Published 2024-08-21

Technologies: github.com/treeverse/lakefs (Go). Vendors: Go.

Executive brief

User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs

Affected products

  • Go github.com/treeverse/lakefs

Related threats