CVE-2024-28847 is a critical Remote Code Execution (RCE) vulnerability affecting OpenMetadata versions prior to 1.2.4. It stems from an expression language injection flaw (CWE-94) in the AlertUtil::validateExpression function, allowing authenticated attackers to execute arbitrary code by sending a crafted PUT request to the /api/v1/events/subscriptions endpoint. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity, requiring only low privileges, and resulting in high impacts to confidentiality, integrity, and availability. The authorization check occurs after the malicious expression is evaluated, making it exploitable. While no public exploit code is listed on Metasploit, Nuclei, or ExploitDB, this vulnerability is actively exploited in the wild, with reports of attackers hijacking OpenMetadata applications in Kubernetes for cryptomining. It has garnered significant community discussion and media coverage, including articles from BleepingComputer and SecurityWeek, highlighting its active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.4CPE matchmatch criteria | cpe:2.3:a:open-metadata:openmetadata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.