CVE-2024-28845: GHSL-2023-235_GHSL-2023-237,GHSL-2023-251_GHSL-2023-252: Pre-authentication RCE in OpenMetadata - CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, CVE-2024-28848
Published Mar 20, 2024
·Updated
OpenMetadata is vulnerable to several SpEL Expression Injections and an authentication bypass leading to pre-authentication Remote Code Execution (RCE).
Affected Software
1 affected component
OpenMetadata OpenMetadata
Event History
Mar 20, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-28845?
CVE-2024-28845 has a high severity rating of 93 due to the risk of pre-authentication remote code execution.
2
How do I fix CVE-2024-28845?
To fix CVE-2024-28845, upgrade OpenMetadata to the latest version that addresses this vulnerability.
3
What types of vulnerabilities are associated with CVE-2024-28845?
CVE-2024-28845 is associated with SpEL Expression Injections and an authentication bypass.
4
What is the impact of CVE-2024-28845?
The impact of CVE-2024-28845 allows attackers to execute arbitrary code remotely without authentication.
5
Is OpenMetadata affected by CVE-2024-28845?
Yes, OpenMetadata is vulnerable to CVE-2024-28845, which involves pre-authentication remote code execution.