GHSL-2023-237: GHSL-2023-235_GHSL-2023-237,GHSL-2023-251_GHSL-2023-252: Pre-authentication RCE in OpenMetadata - CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, CVE-2024-28848
Published Mar 20, 2024
·Updated
OpenMetadata is vulnerable to several SpEL Expression Injections and an authentication bypass leading to pre-authentication Remote Code Execution (RCE).
Affected Software
1 affected component
OpenMetadata OpenMetadata
Event History
Mar 20, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-237?
GHSL-2023-237 is rated with a severity score of 93, indicating a critical risk level.
2
How do I fix GHSL-2023-237?
To fix GHSL-2023-237, you should update OpenMetadata to the latest version as provided in the security advisories.
3
What vulnerabilities are associated with GHSL-2023-237?
GHSL-2023-237 is associated with multiple vulnerabilities including CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, and CVE-2024-28848.
4
What type of attack does GHSL-2023-237 enable?
GHSL-2023-237 enables pre-authentication Remote Code Execution (RCE) through SpEL Expression Injections and authentication bypass.
5
Which software is affected by GHSL-2023-237?
GHSL-2023-237 affects the OpenMetadata software.