VYPR
Vendor

Open Metadata

Products
1
CVEs
15
Across products
15
Status
Private

Products

1

Recent CVEs

15
  • CVE-2024-28255CriMar 15, 2024
    risk 0.66cvss 9.8epss 0.73

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request…

  • CVE-2024-28254HigMar 15, 2024
    risk 0.64cvss 8.8epss 0.46

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎AlertUtil::validateExpression` method evaluates an SpEL expression using `getValue` which by…

  • CVE-2024-28253CriMar 15, 2024
    risk 0.62cvss 9.4epss 0.13

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called…

  • CVE-2024-28848HigMar 15, 2024
    risk 0.58cvss 8.8epss 0.08

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎CompiledRule::validateExpression` method evaluates an SpEL expression using an…

  • CVE-2024-28847HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.02

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the GHSL-2023-250 issue, `AlertUtil::validateExpression` is also called from…

  • CVE-2026-26010HigFeb 11, 2026
    risk 0.49cvss 7.6epss 0.00

    OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically…

  • CVE-2026-46481HigJun 8, 2026
    risk 0.47cvss 8.3epss 0.00

    OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in…

  • CVE-2026-81029HigAug 26, 2026
    risk 0.46cvss 8.1epss 0.01

    OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the…

  • CVE-2025-50466HigAug 8, 2025
    risk 0.46cvss 7.1epss 0.00

    OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL query.

  • CVE-2025-50465HigAug 8, 2025
    risk 0.46cvss 7.1epss 0.00

    OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query.

  • CVE-2025-50468MedAug 8, 2025
    risk 0.42cvss 6.5epss 0.00

    OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to build a SQL query.

  • CVE-2025-50467MedAug 8, 2025
    risk 0.42cvss 6.5epss 0.00

    OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter can be used to build a SQL query.

  • CVE-2026-22244HigJan 8, 2026
    risk 0.40cvss 7.2epss 0.01

    OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version…

  • CVE-2024-55238HigApr 17, 2025
    risk 0.39cvss 7.1epss 0.01

    OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.

  • CVE-2026-100373MedSep 25, 2026
    risk 0.20cvss 4.1epss 0.00

    OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can set webhook…