{"id":"GHSA-hh33-46q4-hwm2","summary":"Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion","details":"### Impact\nExisting lakeFS users who have issued credentials to users who have been deleted.\nCreating a new user with the same username, that user will inherit all of the previous user's credentials lakeFS needs to delete user credentials upon user deletion.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\n### Workarounds\nA possible workaround will be not to reuse usernames that were previously deleted\n\n### References\n_Are there any links users can visit to find out more?_\n","aliases":["CVE-2024-43784","GO-2024-3291"],"modified":"2024-11-27T19:42:16.201526Z","published":"2024-11-26T19:58:20Z","database_specific":{"github_reviewed_at":"2024-11-26T19:58:20Z","nvd_published_at":"2024-11-26T21:15:07Z","cwe_ids":["CWE-281","CWE-287"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-hh33-46q4-hwm2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43784"},{"type":"PACKAGE","url":"https://github.com/treeverse/lakeFS"},{"type":"WEB","url":"https://github.com/treeverse/lakeFS/releases/tag/v1.33.0"}],"affected":[{"package":{"name":"github.com/treeverse/lakefs","ecosystem":"Go","purl":"pkg:golang/github.com/treeverse/lakefs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.33.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-hh33-46q4-hwm2/GHSA-hh33-46q4-hwm2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"}]}