• Get Started
  • Community
    • Slack
    • Events
    • YouTube
  • MCP
  • Data Contracts
  • Resources
    • Documentation
    • Case Studies
    • Blog
    • Product Updates
    • Learning Center
  • OPENMETADATA
    0

We use cookies to improve site navigation, analyze site usage, and enhance your user experience. Click "Accept" to enable cookies or "Reject" to reject cookies.

OpenMetadata Security Vulnerabilities

This page lists all security vulnerabilities fixed in released versions of OpenMetadata.

CVE-2024-28255 Authentication Bypass

This CVE identifies a vulnerability in JWTFilter which could be used to bypass authentication checks for few API endpoints.

Versions affected0.3.0 - 1.2.3
Fixed versions1.2.4 and Later
SeverityCritical
ImpactThis issue may lead to authentication bypass.
AdviceWe advise all OpenMetadata users to promptly upgrade to (>=1.2.4) to mitigate this vulnerability.
Issue Fixed Jan 5th 2024
Issue announced March 16th 2024

CVE-2024-28848 SpEL Injection in GET /api/v1/policies/validation/condition/<expr>

This CVE identified a flaw where it allows the registered users and authenticated users to exploit the API endpoint /api/v1/policies/validation/condition to remotely execute code on the server.

Versions affected0.3.0 - 1.2.3
Fixed versions1.2.4 and Later
SeverityModerate
ImpactThis issue may lead to Remote Code Execution by an Registered and Authenticated User.
AdviceWe advise all OpenMetadata users to promptly upgrade to (>=1.2.4) to mitigate this vulnerability.
Issue FixedJan 5th 2024
Issue announcedMarch 16th 2024

CVE-2024-28847 SpEL Injection in PUT /api/v1/events/subscriptions

This CVE identified a flaw where it allows the registered users and authenticated users to exploit the API endpoint /api/v1/events/subscriptions to remotely execute code on the server.

Versions affected0.3.0 - 1.2.3
Fixed versions1.2.4 and Later
SeverityModerate
ImpactThis issue may lead to Remote Code Execution by an Registered and Authenticated User.
AdviceWe advise all OpenMetadata users to promptly upgrade to (>=1.2.4) to mitigate this vulnerability.
Issue FixedJan 5th 2024
Issue announcedMarch 16th 2024

CVE-2024-28254 SpEL Injection in GET /api/v1/events/subscriptions/validation/condition/<expr>

This CVE identified a flaw where it allows the registered users and authenticated users to exploit the API endpoint GET /api/v1/events/subscriptions/validation/condition/<expr>to remotely execute code on the server.

Versions affectedAll AK versions
Versions affected0.3.0 - 1.2.3
Fixed versions1.2.4 and Later
SeverityHigh
ImpactThis issue may lead to Remote Code Execution by an Registered and Authenticated User.
AdviceWe advise all OpenMetadata users to promptly upgrade to (>=1.2.4) to mitigate this vulnerability.
Issue FixedJan 5th 2024
Issue announcedMarch 16th 2024

CVE-2024-28253 SpEL Injection in `PUT /api/v1/policies`

A possible security vulnerability has been identified in OpenMetadata SPeL rule evalaution. This requires access OpenMetadata APIs as an authenticated user. A authenticated user can send PUT request with a malicious payload to execute a JVM method and run a code on the server.

Versions affected0.3.0 - 1.3.0
Fixed versions1.3.1 and Later
SeverityModerate
ImpactThis issue may lead to Remote Code Execution by an Registered and Authenticated User.
AdviceWe advise all OpenMetadata users to upgrade to (>=1.3.1) to mitigate this vulnerability.
Issue FixedMar 1st 2024
Issue announcedMarch 16th 2024
Unlock the value of data assets with an open-source AI context layer — that includes data cataloging, discovery, governance, data quality, observability, lineage, semantics, and memory for people and AI.
OpenMetadata® and the OpenMetadata logo are trademarks of Collate, Inc.
Copyright © OpenMetadata. All rights reserved.
Docs
  • What is OpenMetadata?
  • APIs
  • Schema
  • Install
  • Ingestion
Community
  • Slack
  • GitHub
  • X
  • Meetup
  • YouTube
Unlock the value of data assets with an open-source AI context layer — that includes data cataloging, discovery, governance, data quality, observability, lineage, semantics, and memory for people and AI.
Copyright OpenMetadata 2026
Site Hosted By
netlify