Datahub Project
Datahub Project Datahub: vulnerabilidades y CVE
Datahub Project Datahub tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-22409 | Alta (8.8) | 0.65% | — | 16 ene 2024 | DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user's profile information. The default privileges gave too many broad… |
| CVE-2023-47640 | Alta (8.8) | 0.36% | — | 14 nov 2023 | DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a SHA-1 HMAC with the frontend secret key. SHA1 with a 10 byte key can be brute forced using… |
| CVE-2023-47629 | Alta (8) | 0.47% | — | 14 nov 2023 | DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user is given an email sign-up link they can… |
| CVE-2023-47628 | Media (4.8) | 0.38% | — | 14 nov 2023 | DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default settings for stateless session which do not set an expiration time for a cookie. Due to this, if a… |
| CVE-2023-25558 | Alta (8.8) | 1.0% | — | 11 feb 2023 | DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The processing of the `id_token` is done in an unsafe manner which is not… |