Junglewise Threat Intelligence

User with permission to write actions can impersonate another user when auth token is configured in environment variable

Severity: low · CVSS 3.1 · Published 2023-12-12

Technologies: github.com/treeverse/lakefs (Go). Vendors: Go.

Executive brief

User with permission to write actions can impersonate another user when auth token is configured in environment variable

Affected products

  • Go github.com/treeverse/lakefs

Related threats