CVE-2024-28253
SpEL Injection in `PUT /api/v1/policies` in OpenMetadata
Record summary
CVE-2024-28253 has a selected CVSS score of 9.4 (critical); EIP currently links 1 Nuclei template.
Description
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called from `EntityRepository.prepareInternal()` which, in turn, gets called from `EntityResource.createOrUpdate()`. Note that even though there is an authorization check (`authorizer.authorize()`), it gets called after `prepareInternal()` gets called and therefore after the SpEL expression has been evaluated. In order to reach this method, an attacker can send a PUT request to `/api/v1/policies` which gets handled by `PolicyResource.createOrUpdate()`. This vulnerability was discovered with the help of CodeQL's Expression language injection (Spring) query and is also tracked as `GHSL-2023-252`. This issue may lead to Remote Code Execution and has been addressed in version 1.3.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 17, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 18, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
OpenMetadataBrowse Netlify / OpenMetadata | VulnCheck | Version data not supplied | |
OpenMetadataBrowse open-metadata / OpenMetadataDefault status: unknown | CVE List | < 1.3.1 | affected |
| Before 1.3.1 | affected | ||
org.open-metadata:openmetadata-serviceBrowse Maven / org.open-metadata:openmetadata-service | GitHub Advisory | Before 1.3.1 · Fixed in 1.3.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALOpenMetaData - SpEL Injection in PUT /api/v1/policiesCVSS 9.4
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called from `EntityRepository.prepareInternal()` which, in turn, gets called from `EntityResource.createOrUpdate()`. Note that even though there is an authorization check (`authorizer.authorize()`), it gets called after `prepareInternal()` gets called and therefore after the SpEL expression has been evaluated. In order to reach this method, an attacker can send a PUT request to `/api/v1/policies` which gets handled by `PolicyResource.createOrUpdate()`. This vulnerability was discovered with the help of CodeQL's Expression language injection (Spring) query and is also tracked as `GHSL-2023-252`. This issue may lead to Remote Code Execution and has been addressed in version 1.3.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Impact
Attackers can execute arbitrary code remotely, potentially leading to full system compromise.
Remediation
Upgrade to version 1.3.1 or later.
Source: ProjectDiscovery