Vulnerabilidades en treeverse
7 resultadosAnálisis Vexday
Treeverse apresenta perfil de risco moderado com 6 vulnerabilidades catalogadas, nenhuma em exploração ativa e sem críticas identificadas. A fraqueza dominante é exposição de informações (CWE-200), com apenas 1 vulnerabilidade publicada nos últimos 90 dias, indicando risco contido e não em escalação recente.
CVE-2025-27100MEDIUMAn authenticated user can crash lakeFS by exhausting server memoryEPSS 0.4%CVE-2026-26187HIGHlakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory accessEPSS 0.4%CVE-2024-43784MEDIUMRe-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to it's deletionEPSS 0.4%CVE-2026-66006MEDIUMlakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefsEPSS 0.3%CVE-2025-64179MEDIUMlakeFS: Unauthenticated access to API usage metricsEPSS 0.3%CVE-2025-68671MEDIUMlakeFS is Missing Timestamp Validation in S3 Gateway AuthenticationEPSS 0.3%CVE-2026-48026HIGHlakeFS vulnerable to stored XSS in rendered markdown previews via raw HTMLEPSS 0.2%