PT-2023-20158 · Datahub · Datahub

Artsploit

+6

·

Published

2023-02-10

·

Updated

2025-12-03

·

CVE-2023-25560

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DataHub (affected versions not specified)
Description The issue concerns the AuthServiceClient in DataHub, which is responsible for managing accounts and authentication. It crafts JSON strings using format strings with user-controlled data, potentially allowing an attacker to manipulate these strings and send them to the backend. This could lead to an authentication bypass, creation of system accounts, and potentially full system compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2023-25560
GHSA-6RPF-5CFG-H8F3

Affected Products

Datahub