Описание
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.
Ссылки
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.11.4 (исключая)
cpe:2.3:a:open-metadata:openmetadata:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00372
Низкий
7.2 High
CVSS3
Дефекты
CWE-1336
CWE-94
Связанные уязвимости
CVSS3: 9.1
github
около 1 месяца назад
OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCE
EPSS
Процентиль: 58%
0.00372
Низкий
7.2 High
CVSS3
Дефекты
CWE-1336
CWE-94