CVE-2024-28255: GHSL-2023-235_GHSL-2023-237,GHSL-2023-251_GHSL-2023-252: Pre-authentication RCE in OpenMetadata - CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, CVE-2024-28848

Published Mar 15, 2024
·
Updated

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The JwtFilter handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to GET /api/v1;v1%2fusers%2flogin/events/subscriptions/validation/condition/111 will match the excluded endpoint condition and therefore will be processed with no JWT validation allowing an attacker to bypass the authentication mechanism and reach any arbitrary endpoint, including the ones listed above that lead to arbitrary SpEL expression injection. This bypass will not work when the endpoint uses the SecurityContext.getUserPrincipal() since it will return null and will throw an NPE. This issue may lead to authentication bypass and has been addressed in version 1.2.4. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as GHSL-2023-237.

Other sources

OpenMetadata is vulnerable to several SpEL Expression Injections and an authentication bypass leading to pre-authentication Remote Code Execution (RCE).

GitHub Security Lab

Affected Software

2 affected components
OpenMetadata OpenMetadata
open-metadata OpenMetadata<1.2.4

Event History

Mar 15, 2024
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 20, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Apr 17, 2024
News Published
via BleepingComputer·09:01 PM
News Published
via BleepingComputer·09:03 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-28255?

CVE-2024-28255 is classified as a critical severity vulnerability due to its potential impact on API authentication.

2

How do I fix CVE-2024-28255?

To fix CVE-2024-28255, upgrade OpenMetadata to version 1.2.4 or later.

3

What software versions are affected by CVE-2024-28255?

CVE-2024-28255 affects OpenMetadata versions up to 1.2.4.

4

What is the nature of the vulnerability in CVE-2024-28255?

CVE-2024-28255 involves inadequate handling of JWT tokens in the JwtFilter component affecting API security.

5

Are there any known exploits for CVE-2024-28255?

As of now, there are no public reports of known exploits for CVE-2024-28255.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203