DataHub是datahub-project开源的一个现代数据栈的元数据平台。 DataHub存在代码问题漏洞,该漏洞源于代理在将数据转发到元数据存储(GMS)时未充分构建URL。攻击者利用该漏洞将来自前端代理的请求重新定向到任何其他服务器并返回结果。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| datahub-project | datahub | < 0.8.45 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25559 | 8.2 HIGH | System account impersonation in DataHub |
| CVE-2023-25560 | 8.2 HIGH | JSON Injection in DataHub |
| CVE-2023-25558 | 7.5 HIGH | Deserialization of untrusted data in DataHub |
| CVE-2023-25562 | 6.9 MEDIUM | Failure to Invalidate Session on Logout in DataHub |
| CVE-2023-25561 | 5.7 MEDIUM | Login fail open on JAAS misconfiguration in DataHub |
No comments yet