Junglewise Threat Intelligence

lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files

Severity: low · CVSS 3.1 · Published 2023-08-14

Technologies: github.com/treeverse/lakefs (Go). Vendors: Go.

Executive brief

lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files

Affected products

  • Go github.com/treeverse/lakefs

Related threats