DataHub是datahub-project开源的一个现代数据栈的元数据平台。 DataHub存在授权问题漏洞。攻击者利用该漏洞可以冒充系统用户帐户并代表其执行任何操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| datahub-project | datahub | < 0.8.45 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25560 | 8.2 HIGH | JSON Injection in DataHub |
| CVE-2023-25557 | 7.5 HIGH | Server-Side Request Forgery in DataHub |
| CVE-2023-25558 | 7.5 HIGH | Deserialization of untrusted data in DataHub |
| CVE-2023-25562 | 6.9 MEDIUM | Failure to Invalidate Session on Logout in DataHub |
| CVE-2023-25561 | 5.7 MEDIUM | Login fail open on JAAS misconfiguration in DataHub |
No comments yet