CVE-2025-64179

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in the /api/v1/usage-report/summary endpoint allows anyone to retrieve aggregate API usage counts. While no sensitive data is disclosed, the endpoint may reveal information about service activity or uptime. This issue is fixed in version 1.71.0 . To workaround the vulnerability, use a load-balancer or application level firewall in order to block the request route /api/v1/usage-report/summary.
Configurations

No configuration.

History

06 Nov 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-06 22:15

Updated : 2025-11-12 16:20


NVD link : CVE-2025-64179

Mitre link : CVE-2025-64179

CVE.ORG link : CVE-2025-64179


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-862

Missing Authorization