S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 10, 2025

CVE-2024-28253 Scanner

CVE-2024-28253 Scanner - Remote Code Execution (RCE) vulnerability in OpenMetaData

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-28253
8.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called from `EntityRepository.prepareInternal()` which, in turn, gets called from `EntityResource.createOrUpdate()`. Note that even though there is an authorization check (`authorizer.authorize()`), it gets called after `prepareInternal()` gets called and therefore after the SpEL expression has been evaluated. In order to reach this method, an attacker can send a PUT request to `/api/v1/policies` which gets handled by `PolicyResource.createOrUpdate()`. This vulnerability was discovered with the help of CodeQL's Expression language injection (Spring) query and is also tracked as `GHSL-2023-252`. This issue may lead to Remote Code Execution and has been addressed in version 1.3.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
OpenMetadataby open-metadata
< 1.3.1
openmetadataby openmetadata
AFFECTED< 1.3.1SAFE ✓≥ 1.3.1
Updated Aug 22, 2026View on NVD →
Detail

OpenMetaData is commonly deployed by organizations to ensure efficient data management through discovery, observability, and governance solutions. It serves a diverse range of industries, offering centralized metadata repository services which include in-depth lineage tracking and collaborations among various teams. Through its specialized features, OpenMetaData is instrumental in unifying data insights, thereby optimizing organizations' data governance strategies. A wide number of digital enterprises and data stewards rely on this platform for systemizing metadata operations and enhancing decision-making processes. Its versatility finds applications in multiple contexts, from small-scale team operations to large, complex enterprise ecosystems. OpenMetaData's ability to provide seamless data management makes it a preferred choice among data-driven enterprises seeking to scale efficiently.

The vulnerability in this scenario involves a Remote Code Execution (RCE) flaw identified in the OpenMetaData software. This critical flaw allows attackers to execute arbitrary code remotely, posing significant risks if exploited. The SpEL injection within the PUT method to /api/v1/policies is the root cause, enabling execution commands potentially leading to a full system compromise. Such vulnerabilities can bypass authorization checks, making systems highly susceptible to control by unauthorized entities. Addressing such issues is crucial, as leaving them unpatched can expose systems to external threats and facilitate unauthorized access to sensitive data. The detection of RCE vulnerabilities within OpenMetaData emphasizes the need for prompt and adequate security responses to mitigate associated risks.

In technical terms, the RCE vulnerability manifests from improper handling of SpEL injection vulnerabilities within OpenMetaData, specifically in its "/api/v1/policies" endpoint. When a malicious PUT request is made, exploiting conditional authorization checks and resulting in unauthorized code execution, attackers can exploit the system's lack of input verification. During exploitation, the system inadequately checks policy creation, allowing malicious Java operations to be executed. Vulnerable expressions, especially within the "condition" parameter of policy rules, offer points of entry for arbitrary code execution. Thus, ensuring thorough code review and validation checks, especially in dynamically generated policies, are foundational to mitigating this vulnerability.

If successfully exploited, this RCE vulnerability could lead to far-reaching consequences such as unauthorized system access and potential data breaches. Adversaries could gain control over affected systems, leading to data theft, system corruption, or further network infiltration. In extreme cases, this vulnerability might allow for lateral movement within a network, escalating privileges, and targeting additional assets. Organizations found vulnerable to such exploitation may face operational disruptions, financial loss, and reputational damage. Moreover, exposure of confidential data could result in compliance violations and loss of stakeholder trust.

REFERENCES

Solution Advice
  • Upgrade to version 1.3.1 or later to mitigate the vulnerability.
  • Implement strict input validation and sanitation to prevent similar injection vulnerabilities.
  • Restrict unauthorized access by enhancing security protocols and authentication processes.
  • Continuously monitor and audit policy changes and system activities for suspicious behaviors.
  • Apply security patches and updates promptly to reduce vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.