CVE-2024-28255: GHSL-2023-235_GHSL-2023-237,GHSL-2023-251_GHSL-2023-252: Pre-authentication RCE in OpenMetadata - CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, CVE-2024-28848
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The JwtFilter handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to GET /api/v1;v1%2fusers%2flogin/events/subscriptions/validation/condition/111 will match the excluded endpoint condition and therefore will be processed with no JWT validation allowing an attacker to bypass the authentication mechanism and reach any arbitrary endpoint, including the ones listed above that lead to arbitrary SpEL expression injection. This bypass will not work when the endpoint uses the SecurityContext.getUserPrincipal() since it will return null and will throw an NPE. This issue may lead to authentication bypass and has been addressed in version 1.2.4. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as GHSL-2023-237.
Other sources
OpenMetadata is vulnerable to several SpEL Expression Injections and an authentication bypass leading to pre-authentication Remote Code Execution (RCE).
— GitHub Security Lab
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28255?
CVE-2024-28255 is classified as a critical severity vulnerability due to its potential impact on API authentication.
How do I fix CVE-2024-28255?
To fix CVE-2024-28255, upgrade OpenMetadata to version 1.2.4 or later.
What software versions are affected by CVE-2024-28255?
CVE-2024-28255 affects OpenMetadata versions up to 1.2.4.
What is the nature of the vulnerability in CVE-2024-28255?
CVE-2024-28255 involves inadequate handling of JWT tokens in the JwtFilter component affecting API security.
Are there any known exploits for CVE-2024-28255?
As of now, there are no public reports of known exploits for CVE-2024-28255.