GHSL-2023-252: GHSL-2023-235_GHSL-2023-237,GHSL-2023-251_GHSL-2023-252: Pre-authentication RCE in OpenMetadata - CVE-2024-28253, CVE-2024-28254, CVE-2024-28255, CVE-2024-28845, CVE-2024-28848
Published Mar 20, 2024
·Updated
OpenMetadata is vulnerable to several SpEL Expression Injections and an authentication bypass leading to pre-authentication Remote Code Execution (RCE).
Affected Software
1 affected component
OpenMetadata OpenMetadata
Event History
Mar 20, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-252?
GHSL-2023-252 has a severity risk score of 95, indicating a high level of threat.
2
How do I fix GHSL-2023-252?
To fix GHSL-2023-252, update OpenMetadata to the latest version that addresses the vulnerability.
3
What types of vulnerabilities are associated with GHSL-2023-252?
GHSL-2023-252 is associated with pre-authentication Remote Code Execution and several SpEL Expression Injections.
4
Who is affected by GHSL-2023-252?
Any users utilizing vulnerable versions of OpenMetadata are affected by GHSL-2023-252.
5
What is the impact of GHSL-2023-252?
The impact of GHSL-2023-252 allows attackers to execute arbitrary code on the server prior to authentication.