An authenticated user can crash lakeFS by exhausting server memory. This is an authenticated denial-of-service issue.
This problem has been patched and exists in versions 1.49.1 and below
On S3 backends, configure
# ...
blockstore:
  s3:
    disable_pre_signed_multipart: true
or set environment variable LAKEFS_BLOCKSTORE_S3_DISABLE_PRE_SIGNED_MULTIPART to true.
Are there any links users can visit to find out more?
{
    "nvd_published_at": "2025-02-21T00:15:09Z",
    "severity": "MODERATE",
    "github_reviewed_at": "2025-02-21T21:43:16Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-400"
    ]
}