Vendor
high
advisory
Authentication Token Theft via OpenMetadata Redirect Vulnerability
2 TTPs 1 CVEOpenMetadata versions prior to 2.0.0 contain a critical vulnerability in the SAML, OIDC, and OAuth2 handlers that allows attackers to redirect sensitive authentication tokens to external, attacker-controlled domains.
OpenMetadata
2t
1c
high
advisory
OpenMetadata TEST_CONNECTION Workflow Leaks JWT and Database Password
2 rules 2 TTPsOpenMetadata version 1.12.1 is vulnerable to an information disclosure issue where a non-admin user can trigger a TEST_CONNECTION workflow for a Database Service and receive the cleartext database password and the ingestion bot JWT in the HTTP response, enabling privilege escalation.
openmetadata-service +1
openmetadata
information-disclosure
jwt-leak
credential-access
2r
2t