← Vulnerability feed

Vulnerability record · CVE-2024-28255 · published 15 March 2024

CVE-2024-28255: OpenMetadata JwtFilter authentication bypass via path parameters

Open Metadata · Openmetadata

OpenMetadata's JwtFilter skips JWT validation when a request path matches an excluded endpoint, but path parameters let an attacker make any path contain an excluded string. This allows unauthenticated requests to reach arbitrary endpoints, including ones vulnerable to SpEL expression injection. The flaw is fixed in version 1.2.4 and has no known workarounds.

9.8 CVSS 3.1 Critical EPSS 73% · top 0.6% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to `GET /api/v1;v1%2fusers%2flogin/events/subscriptions/validation/condition/111` will match the excluded endpoint condition and therefore will be processed with no JWT validation allowing an attacker to bypass the authentication mechanism and reach any arbitrary endpoint, including the ones listed above that lead to arbitrary SpEL expression injection. This bypass will not work when the endpoint uses the `SecurityContext.getUserPrincipal()` since it will return `null` and will throw an NPE. This issue may lead to authentication bypass and has been addressed in version 1.2.4. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as `GHSL-2023-237`.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication required, and high EPSS probability make this an urgent authentication bypass.

What it is

OpenMetadata's JwtFilter skips JWT validation when a request path matches an excluded endpoint, but path parameters let an attacker make any path contain an excluded string. This allows unauthenticated requests to reach arbitrary endpoints, including ones vulnerable to SpEL expression injection. The flaw is fixed in version 1.2.4 and has no known workarounds.

Impact

An attacker can bypass authentication entirely and reach any endpoint, including those that permit arbitrary SpEL expression injection, potentially leading to remote code execution. Confidentiality, integrity, and availability are all rated high in the CVSS vector.

Attack surface

Reachable over the network via HTTP requests to the OpenMetadata API; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The bypass fails on endpoints that call SecurityContext.getUserPrincipal() because it returns null and throws an NPE.

Exploitation

EPSS is 0.73255 (99.4th percentile), indicating a high probability of exploitation activity, and references are tagged Exploit and Vendor Advisory. The CVE is not listed in CISA KEV.

What to do

  • Upgrade OpenMetadata to version 1.2.4 or later, which addresses the issue.
  • If immediate upgrade is not possible, restrict network access to the OpenMetadata API to trusted sources only, since no workarounds exist.
  • Review and harden any endpoints that accept SpEL expressions or similar dynamic evaluation, as they are the likely post-bypass target.
  • Monitor for requests containing path parameters with encoded slashes or semicolons that could match excluded endpoint patterns.

Detection

  • Inspect HTTP request logs for paths containing semicolons or encoded slashes (e.g., %2f) that may be used to bypass the JwtFilter.
  • Alert on unauthenticated requests reaching endpoints that should require JWT validation, especially those involving expression evaluation.
  • Correlate requests to excluded endpoint patterns with subsequent calls to sensitive endpoints from the same source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-28255 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-50465Open-metadata openmetadata sql injection vulnerabilityOpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitio…EPSS 0.32%8.8CVE-2024-55238Open-metadata openmetadata sql injection vulnerabilityOpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO i…EPSS 0.61%8.8CVE-2024-28254OpenMetadata SpEL injection in alert condition validation allows RCEOpenMetadata's AlertUtil::validateExpression evaluates user-supplied SpEL with a StandardEvaluationContext, letting expressions reach Java classes su…EPSS 46%analysed8.8CVE-2024-28847Open-metadata openmetadata code injection vulnerabilityOpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…EPSS 2.4%8.8CVE-2024-28848Open-metadata openmetadata code injection vulnerabilityOpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…EPSS 7.9%8.8CVE-2024-28253Open-metadata openmetadata code injection vulnerabilityOpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…EPSS 13%8.5CVE-2026-22244Open-metadata openmetadata code injection vulnerabilityOpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection…EPSS 1.3%7.6CVE-2026-26010Open-metadata openmetadata improper privilege management vulnerabilityOpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-b…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2024-28255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.