Vulnerability record · CVE-2024-28254 · published 15 March 2024
CVE-2024-28254: OpenMetadata SpEL injection in alert condition validation allows RCE
Open Metadata · Openmetadata
OpenMetadata's AlertUtil::validateExpression evaluates user-supplied SpEL with a StandardEvaluationContext, letting expressions reach Java classes such as java.lang.Runtime. The /api/v1/events/subscriptions/validation/condition/<expression> endpoint passes attacker-controlled data into that method, and the affected path never calls Authorizer.authorize(). Any authenticated non-admin user can therefore execute arbitrary OS commands.
Description
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `AlertUtil::validateExpression` method evaluates an SpEL expression using `getValue` which by default uses the `StandardEvaluationContext`, allowing the expression to reach and interact with Java classes such as `java.lang.Runtime`, leading to Remote Code Execution. The `/api/v1/events/subscriptions/validation/condition/<expression>` endpoint passes user-controlled data `AlertUtil::validateExpession` allowing authenticated (non-admin) users to execute arbitrary system commands on the underlaying operating system. In addition, there is a missing authorization check since `Authorizer.authorize()` is never called in the affected path and, therefore, any authenticated non-admin user is able to trigger this endpoint and evaluate arbitrary SpEL expressions leading to arbitrary command execution. This vulnerability was discovered with the help of CodeQL's Expression language injection (Spring) query and is also tracked as `GHSL-2023-235`. This issue may lead to Remote Code Execution and has been addressed in version 1.2.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, low privileges and full confidentiality, integrity and availability impact, plus a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
OpenMetadata's AlertUtil::validateExpression evaluates user-supplied SpEL with a StandardEvaluationContext, letting expressions reach Java classes such as java.lang.Runtime. The /api/v1/events/subscriptions/validation/condition/<expression> endpoint passes attacker-controlled data into that method, and the affected path never calls Authorizer.authorize(). Any authenticated non-admin user can therefore execute arbitrary OS commands.
Impact
An attacker with a low-privileged authenticated account gains arbitrary command execution on the OpenMetadata host, compromising confidentiality, integrity and availability of the server and any data it can reach.
Attack surface
Reachable over the network via the HTTP endpoint /api/v1/events/subscriptions/validation/condition/<expression>; it requires authentication but only a non-admin account, and no user interaction. The missing authorization check means no elevated role is needed.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged in the record, but EPSS is 0.457 (98.7th percentile), indicating elevated predicted exploitation activity. The vendor advisory confirms the flaw and states there are no known workarounds.
What to do
- Upgrade OpenMetadata to version 1.2.4 or later, which addresses the issue.
- If immediate upgrade is not possible, restrict network access to the /api/v1/events/subscriptions/validation/condition/ endpoint and limit it to trusted administrative users.
- Audit and reduce the number of authenticated non-admin accounts that can reach the OpenMetadata API until patched.
- Monitor for and block SpEL payload patterns such as T(java.lang.Runtime) or ProcessBuilder in requests to the validation endpoint.
- Review server logs for unexpected child processes spawned by the OpenMetadata service account.
Detection
- Alert on HTTP requests to /api/v1/events/subscriptions/validation/condition/ containing SpEL constructs like T(, Runtime, exec, or ProcessBuilder.
- Monitor OpenMetadata service processes for unexpected child process creation (for example shell or command interpreters) using EDR or process auditing.
- Baseline and alert on anomalous outbound network connections originating from the OpenMetadata host.
- Review application and access logs for validation endpoint calls from non-admin accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-28254 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-28254), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.