GHSL-2023-251: GHSL-2023-235_GHSL-2023-237,GHSL-2023-251_GHSL-2023-252: Pre-authentication RCE in OpenMetadata - CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, CVE-2024-28848
Published Mar 20, 2024
·Updated
OpenMetadata is vulnerable to several SpEL Expression Injections and an authentication bypass leading to pre-authentication Remote Code Execution (RCE).
Affected Software
1 affected component
OpenMetadata OpenMetadata
Event History
Mar 20, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-251?
GHSL-2023-251 has a severity rating of 93, indicating a critical risk level.
2
How do I fix GHSL-2023-251?
To fix GHSL-2023-251, upgrade OpenMetadata to the latest version that addresses the identified vulnerabilities.
3
What vulnerabilities are associated with GHSL-2023-251?
GHSL-2023-251 is linked to multiple vulnerabilities, including SpEL Expression Injections and an authentication bypass.
4
Can GHSL-2023-251 result in data breaches?
Yes, GHSL-2023-251 can lead to pre-authentication Remote Code Execution (RCE), posing significant risks of data breaches.
5
Which software is affected by GHSL-2023-251?
GHSL-2023-251 specifically affects OpenMetadata software, making it crucial for users to address the vulnerabilities.