CVE-2025-50465: SQL Injection
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50465?
CVE-2025-50465 has a high severity due to its SQL Injection vulnerability that can lead to unauthorized information disclosure.
How do I fix CVE-2025-50465?
To fix CVE-2025-50465, update OpenMetadata to version 1.4.5 or later where the vulnerability has been addressed.
What are the potential impacts of CVE-2025-50465?
The potential impacts of CVE-2025-50465 include data leakage and manipulation of the database through crafted SQL queries.
Which versions of OpenMetadata are affected by CVE-2025-50465?
OpenMetadata versions up to and including 1.4.4 are affected by CVE-2025-50465.
Who is responsible for addressing CVE-2025-50465?
The maintainers of OpenMetadata are responsible for addressing CVE-2025-50465 by releasing patches and updates.