← Retour
CVE-2026-48026
high
CVSS 8.7
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
Résumé
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-48026** a été découverte dans CVE-2026-48026.
Des attaquants peuvent cibler un point d'entrée spécifique comme ``README.md`` à distance pour détourner le produit.
Des informations confidentielles peuvent être exposées. Score CVSS : 8.7/10.
Action : mettez à jour CVE-2026-48026 vers **1.81.1** ou supérieur.
En cas de doute, contactez votre service informatique ou cherchez « CVE-2026-48026 CVE-2026-48026 » sur le site de l'éditeur.
CVE-2026-48026 (CVE-2026-48026) — CWE-79 / CVSS v3 8.7
Vecteur d'attaque : distant (réseau)
Surface d'attaque : `README.md`
Versions affectées : `<=1.81.0`
Correctif : `1.81.1` — appliquer immédiatement
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
lakeFSのWeb UIにおけるXSSの脆弱性。
📍 Périmètre concerné
バージョン1.81.1未満のオープンソースエディションおよび1.84.0未満のエンタープライズエディション。
🔥 Gravité
任意のHTML/JavaScriptを実行可能であり、高度な権限を持つ攻撃を許す可能性がある。
🔧 Comment corriger
lakeFSはv1.81.1、lakeFSエンタープライズはv1.84.0にアップデートする。
🛡️ Contournement
エンタープライズエディションにおいて、一時的にMarkdownレンダリングを無効化する設定を追加。
🔍 Détection
指定されたバージョン以下であれば影響を受ける。
Références
- web [email protected]
- web [email protected]