PT-2026-6808 · Datahub · Datahub

Arad Inbar

+2

·

Publicado

2026-02-06

·

Atualizado

2026-02-06

·

CVE-2026-25644

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DataHub versions prior to 1.3.1.8
Description DataHub, an open-source metadata platform, has an issue in its LDAP ingestion source. Specifically, versions before 1.3.1.8 are susceptible to a man-in-the-middle (MITM) attack due to a TLS downgrade. This allows an attacker to intercept and potentially modify communications between the DataHub platform and the LDAP server.
Recommendations Update to DataHub version 1.3.1.8 or later.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25644
GHSA-J34H-X7QG-4QW5

Produtos afetados

Datahub