{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-10T11:32:57.415","vulnerabilities":[{"cve":{"id":"CVE-2025-64179","sourceIdentifier":"security-advisories@github.com","published":"2025-11-06T22:15:44.463","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in the /api/v1/usage-report/summary endpoint allows anyone to retrieve aggregate API usage counts. While no sensitive data is disclosed, the endpoint may reveal information about service activity or uptime. This issue is fixed in version 1.71.0 . To workaround the vulnerability, use a load-balancer or application level firewall in order to block the request route /api/v1/usage-report/summary."},{"lang":"es","value":"lakeFS es una herramienta de código abierto que transforma el almacenamiento de objetos en repositorios tipo Git. En las versiones 1.69.0 e inferiores, la falta de autenticación en el endpoint /api/v1/usage-report/summary permite a cualquiera recuperar recuentos agregados de uso de la API. Aunque no se divulga ningún dato sensible, el endpoint puede revelar información sobre la actividad o el tiempo de actividad del servicio. Este problema está solucionado en la versión 1.71.0. Para solucionar la vulnerabilidad, utilice un balanceador de carga o un cortafuegos a nivel de aplicación para bloquear la ruta de solicitud /api/v1/usage-report/summary."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/treeverse/lakeFS/commit/1c8adab852dac2387fcb00a256402b308a610c60","source":"security-advisories@github.com"},{"url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-h238-5mwf-8xw8","source":"security-advisories@github.com"}]}}]}