GHSL-2023-235: _GHSL-2023-237,GHSL-2023-251_GHSL-2023-252: Pre-authentication RCE in OpenMetadata - CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, CVE-2024-28848
Published Mar 20, 2024
·Updated
OpenMetadata is vulnerable to several SpEL Expression Injections and an authentication bypass leading to pre-authentication Remote Code Execution (RCE).
Affected Software
1 affected component
OpenMetadata OpenMetadata
Event History
Mar 20, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-235?
GHSL-2023-235 has a risk rating of 95, indicating a high level of severity.
2
How do I fix GHSL-2023-235?
To remediate GHSL-2023-235, update OpenMetadata to version 1.2.2 or later.
3
What type of vulnerability is associated with GHSL-2023-235?
GHSL-2023-235 involves pre-authentication remote code execution due to SpEL Expression Injections and authentication bypass.
4
Is there a known exploit for GHSL-2023-235?
Yes, GHSL-2023-235 has been identified as having potential exploits due to its pre-authentication remote code execution capabilities.
5
Which software is affected by GHSL-2023-235?
OpenMetadata is the software that is affected by the vulnerabilities outlined in GHSL-2023-235.