CVE-2024-28255 describes a critical authentication bypass vulnerability in OpenMetadata, a unified platform for data discovery and governance. Attackers can exploit a flaw in the JwtFilter's path exclusion logic, specifically by using path parameters, to bypass JWT validation and access arbitrary endpoints. This allows for authentication bypass and potential arbitrary SpEL expression injection, leading to full compromise of confidentiality, integrity, and availability. The vulnerability has a CVSS score of 9.8 (CRITICAL), an EPSS score indicating high exploitability, and is actively exploited in the wild, with public exploit code available in Metasploit and Nuclei templates. Media coverage and community discussion confirm active exploitation, including its use in Kubernetes cryptomining attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.4CPE matchmatch criteria | cpe:2.3:a:open-metadata:openmetadata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.