漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
An authenticated user can crash lakeFS by exhausting server memory
Vulnerability Description
lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting server memory. This is an authenticated denial-of-service issue. This problem has been patched in version 1.50.0. Users on versions 1.49.1 and below are affected. Users are advised to upgrade. Users unable to upgrade should either set the environment variable `LAKEFS_BLOCKSTORE_S3_DISABLE_PRE_SIGNED_MULTIPART` to `true` or configure the `disable_pre_signed_multipart` key to true in their config yaml.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
lakeFS 资源管理错误漏洞
Vulnerability Description
lakeFS是Treeverse开源的一款开源工具,可将您的对象存储转换为类似 Git 的存储库。 lakeFS 1.50.0之前版本存在资源管理错误漏洞,该漏洞源于存在内存耗尽,会导致认证用户触发服务器拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A