Impact
The vulnerability is an authentication bypass in the /setup_comm_prefs endpoint, allowing an attacker to POST arbitrary operator metadata such as email, name, and company after the initial setup has completed. By modifying these fields, a malicious actor can also alter security update preferences, disable security communications, and trigger falsified telemetry events that appear to originate from the legitimate installation ID. The flaw exposes the service to data integrity and availability issues rather than direct confidentiality leaks.
Affected Systems
Treeverse lakeFS versions up to and including 1.83.0 are impacted. The fix is contained in commit 71a45ee and subsequent releases.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium impact, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers only need unauthenticated HTTP access to the /setup_comm_prefs endpoint, making it a remote, web‑based exploitation path.
OpenCVE Enrichment