Executive brief
User with permission to write actions can impersonate another user when auth token is configured in environment variable
Affected products
- Go github.com/treeverse/lakefs
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2023-12-12
Technologies: github.com/treeverse/lakefs (Go). Vendors: Go.
User with permission to write actions can impersonate another user when auth token is configured in environment variable