CVE-2026-100373
- EPSS 0.26%
- Veröffentlicht 25.09.2026 19:38:29
- Zuletzt bearbeitet 25.09.2026 21:17:21
OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscripti...
CVE-2026-81029
- EPSS 0.3%
- Veröffentlicht 26.08.2026 15:44:57
- Zuletzt bearbeitet 16.09.2026 13:42:46
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or regi...
CVE-2026-46481
- EPSS 0.24%
- Veröffentlicht 08.06.2026 16:51:06
- Zuletzt bearbeitet 23.07.2026 07:10:00
OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext d...
CVE-2026-26010
- EPSS 0.33%
- Veröffentlicht 11.02.2026 21:16:21
- Zuletzt bearbeitet 13.02.2026 21:34:48
OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly ...
CVE-2026-22244
- EPSS 0.77%
- Veröffentlicht 08.01.2026 15:12:51
- Zuletzt bearbeitet 31.08.2026 23:16:35
OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the...
CVE-2025-50468
- EPSS 0.3%
- Veröffentlicht 08.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:49:32
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to build a SQL query.
CVE-2025-50465
- EPSS 0.32%
- Veröffentlicht 08.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:48:13
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query.
CVE-2025-50466
- EPSS 0.32%
- Veröffentlicht 08.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:48:56
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL query.
CVE-2025-50467
- EPSS 0.26%
- Veröffentlicht 08.08.2025 00:00:00
- Zuletzt bearbeitet 11.08.2025 14:49:15
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter can be used to build a SQL query.
CVE-2024-55238
- EPSS 0.57%
- Veröffentlicht 17.04.2025 16:15:27
- Zuletzt bearbeitet 24.04.2025 12:47:25
OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.