lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs, or compromised systems) can replay that request until credentials are rotated, even after the request is intended to expire. This vulnerability is fixed in 1.75.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-15 23:15
Updated : 2026-01-16 15:55
NVD link : CVE-2025-68671
Mitre link : CVE-2025-68671
CVE.ORG link : CVE-2025-68671
JSON object : View
Products Affected
No product.
CWE
CWE-294
Authentication Bypass by Capture-replay
