Product
OpenMetadata versions prior to 2.0.0 contain a critical vulnerability in the SAML, OIDC, and OAuth2 handlers that allows attackers to redirect sensitive authentication tokens to external, attacker-controlled domains.