目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-81029— OpenMetadata 2.0.0 之前JWT泄露漏洞

一分钟漏洞结论

影响对象
open-metadata OpenMetadata
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

OpenMetadata 会接受调用方提供的、用于认证后的重定向目标地址,并将签发的令牌附加到该地址中。SamlLoginServlet 读取回调请求参数并将其存入 HTTP 会话中,但并未将其与任何已配置或已注册的目标地址进行比对;随后的断言消费者 Servlet 会将该存储值格式化为一个携带新签发的 JWT 以及账户邮箱和姓名的 URL,并据此发送重定向请求。OIDC 和 OAuth2 处理器遵循相同的模式,使用自身的重定向参数和签发的身份令牌。因此,当请求指定一个由攻击者控制的目标地址时,服务器会将完成登录的

CVSS 8.1 · High

影响版本矩阵 1

厂商产品 版本范围状态
open-metadata OpenMetadata < 2.0.0 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-81029 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI
来源: CVE Program / CVE List V5
Vulnerability Description
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats that stored value into a URL carrying the freshly issued JWT together with the account's email and name before sending the redirect. The OIDC and OAuth2 handler follows the same pattern with its own redirect parameter and the issued identity token. A request naming a destination the attacker controls therefore causes the server to deliver a valid token for whoever completes the login to that destination. Because the token authenticates API calls as that account, a user who follows such a link and authenticates hands over control of their account. Version 2.0.0 removes the caller-supplied callback parameter; no 1.x release validates it.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
open-metadata OpenMetadata 0 ~ 2.0.0 -

二、漏洞 CVE-2026-81029 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-81029 的情报信息

登录查看更多情报信息。

CVE-2026-81029 厂商安全公告 (1)

CVE-2026-81029 概念验证 (1)

CVE-2026-81029 安全博客文章 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-81029

暂无评论


发表评论