Open-metadata
Open-metadata Openmetadata: vulnerabilidades y CVE
Open-metadata Openmetadata tiene 15 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100373 | Media (5.1) | 0.26% | — | 25 sept 2026 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to… |
| CVE-2026-81029 | Alta (8.5) | 0.55% | — | 26 ago 2026 | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it… |
| CVE-2026-46481 | Alta (8.3) | 0.42% | — | 8 jun 2026 | OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST… |
| CVE-2026-26010 | Alta (7.6) | 0.36% | — | 11 feb 2026 | OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only… |
| CVE-2026-22244 | Alta (8.5) | 1.3% | — | 8 ene 2026 | OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have… |
| CVE-2025-50468 | Media (6.5) | 0.30% | — | 8 ago 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to build a SQL query. |
| CVE-2025-50467 | Media (6.5) | 0.26% | — | 8 ago 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter can be used to… |
| CVE-2025-50466 | Media (6.5) | 0.33% | — | 8 ago 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL… |
| CVE-2025-50465 | Alta (8.8) | 0.32% | — | 8 ago 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL… |
| CVE-2024-55238 | Alta (8.8) | 0.61% | — | 17 abr 2025 | OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build… |
| CVE-2024-28848 | Alta (8.8) | 7.9% | — | 15 mar 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `CompiledRule::validateExpression` method… |
| CVE-2024-28847 | Alta (8.8) | 2.4% | — | 15 mar 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the GHSL-2023-250 issue,… |
| CVE-2024-28255 | Crítica (9.8) | 73% | — | 15 mar 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication… |
| CVE-2024-28254 | Alta (8.8) | 46% | — | 15 mar 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `AlertUtil::validateExpression` method… |
| CVE-2024-28253 | Alta (8.8) | 13% | — | 15 mar 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.