PT-2025-17195 · Unknown · Openmetadata

Published

2025-04-17

·

Updated

2025-04-22

·

CVE-2024-55238

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenMetadata versions 1.4.1 and earlier
Description The issue allows an attacker to extract information from the database. This is achieved through the listCount function in the WorkflowDAO interface, where the workflowtype and status parameters can be manipulated to build a SQL query.
Recommendations For OpenMetadata versions 1.4.1 and earlier, as a temporary workaround, consider restricting the use of the workflowtype and status parameters in the listCount function of the WorkflowDAO interface until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-55238
GHSA-X8PM-WRG2-MQMX

Affected Products

Openmetadata