CVE-2026-25644
- EPSS 0.04%
- Veröffentlicht 06.02.2026 22:40:12
- Zuletzt bearbeitet 20.02.2026 21:03:18
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.
CVE-2023-25557
- EPSS 1.21%
- Veröffentlicht 11.02.2023 01:23:26
- Zuletzt bearbeitet 03.12.2025 21:05:03
DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to the backend. The goal of this proxy is to perform authentication if needed and forward HTTP requests to the DataHub Meta...
CVE-2023-25559
- EPSS 0.22%
- Veröffentlicht 11.02.2023 01:23:26
- Zuletzt bearbeitet 03.12.2025 21:05:03
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the user the frontend is sending the...
CVE-2023-25560
- EPSS 0.29%
- Veröffentlicht 11.02.2023 01:23:26
- Zuletzt bearbeitet 03.12.2025 21:05:03
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, verifying credentials, resetting them or requesting access tokens, crafts multiple JSON strings using format strings with user-contr...
CVE-2023-25561
- EPSS 0.52%
- Veröffentlicht 11.02.2023 01:23:26
- Zuletzt bearbeitet 03.12.2025 21:05:03
DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Service (JAAS) authentication and that system is given a configuration which contains an error, the authentication for the system will f...
CVE-2023-25562
- EPSS 0.08%
- Veröffentlicht 11.02.2023 01:23:26
- Zuletzt bearbeitet 03.12.2025 21:05:03
DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on new sign-in events and not on logout events. Any authentication checks using the `AuthUtils.hasValidSessionCookie()` method could ...
CVE-2022-39366
- EPSS 0.23%
- Veröffentlicht 28.10.2022 17:15:23
- Zuletzt bearbeitet 03.12.2025 21:05:03
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user i...