PT-2025-32376 · Unknown · Openmetadata

·

CVE-2025-50465

·

Published

2025-08-08

·

Updated

2025-08-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenMetadata versions prior to 1.4.5
Description OpenMetadata is susceptible to a SQL injection issue. An attacker can extract information from the database through the listCount function within the TestDefinitionDAO interface. The testPlatform parameter is used to construct a SQL query, enabling the injection.
Recommendations Update to OpenMetadata version 1.4.5 or later. As a temporary workaround, restrict access to the TestDefinitionDAO interface. Avoid using the testPlatform parameter in the affected function until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-50465

Affected Products

Openmetadata