PT-2024-19399 · Datahub · Datahub

Amit-Laish

+1

·

Published

2024-01-16

·

Updated

2024-01-25

·

CVE-2024-22409

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataHub versions prior to 0.12.1
Description DataHub is an open-source metadata platform. In affected versions, a low privileged user could remove a user, edit group members, or edit another user's profile information due to overly broad default privileges. This issue can result in privilege escalation for lower privileged users up to admin privileges if a group with admin privileges exists. The issue may not impact instances that have modified default privileges.
Recommendations For versions prior to 0.12.1, upgrade to version 0.12.1 to address the issue. As a temporary workaround, consider modifying the default privileges to constrain the permissions of low privileged users until the upgrade can be applied. Restrict access to user management and group member editing features to minimize the risk of exploitation.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-22409
GHSA-X3V6-R479-M4XV

Affected Products

Datahub