Vulnerability record · CVE-2024-28255 · published 15 March 2024
CVE-2024-28255: OpenMetadata JwtFilter authentication bypass via path parameters
Open Metadata · Openmetadata
OpenMetadata's JwtFilter skips JWT validation when a request path matches an excluded endpoint, but path parameters let an attacker make any path contain an excluded string. This allows unauthenticated requests to reach arbitrary endpoints, including ones vulnerable to SpEL expression injection. The flaw is fixed in version 1.2.4 and has no known workarounds.
Description
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to `GET /api/v1;v1%2fusers%2flogin/events/subscriptions/validation/condition/111` will match the excluded endpoint condition and therefore will be processed with no JWT validation allowing an attacker to bypass the authentication mechanism and reach any arbitrary endpoint, including the ones listed above that lead to arbitrary SpEL expression injection. This bypass will not work when the endpoint uses the `SecurityContext.getUserPrincipal()` since it will return `null` and will throw an NPE. This issue may lead to authentication bypass and has been addressed in version 1.2.4. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as `GHSL-2023-237`.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication required, and high EPSS probability make this an urgent authentication bypass.
What it is
OpenMetadata's JwtFilter skips JWT validation when a request path matches an excluded endpoint, but path parameters let an attacker make any path contain an excluded string. This allows unauthenticated requests to reach arbitrary endpoints, including ones vulnerable to SpEL expression injection. The flaw is fixed in version 1.2.4 and has no known workarounds.
Impact
An attacker can bypass authentication entirely and reach any endpoint, including those that permit arbitrary SpEL expression injection, potentially leading to remote code execution. Confidentiality, integrity, and availability are all rated high in the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to the OpenMetadata API; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The bypass fails on endpoints that call SecurityContext.getUserPrincipal() because it returns null and throws an NPE.
Exploitation
EPSS is 0.73255 (99.4th percentile), indicating a high probability of exploitation activity, and references are tagged Exploit and Vendor Advisory. The CVE is not listed in CISA KEV.
What to do
- Upgrade OpenMetadata to version 1.2.4 or later, which addresses the issue.
- If immediate upgrade is not possible, restrict network access to the OpenMetadata API to trusted sources only, since no workarounds exist.
- Review and harden any endpoints that accept SpEL expressions or similar dynamic evaluation, as they are the likely post-bypass target.
- Monitor for requests containing path parameters with encoded slashes or semicolons that could match excluded endpoint patterns.
Detection
- Inspect HTTP request logs for paths containing semicolons or encoded slashes (e.g., %2f) that may be used to bypass the JwtFilter.
- Alert on unauthenticated requests reaching endpoints that should require JWT validation, especially those involving expression evaluation.
- Correlate requests to excluded endpoint patterns with subsequent calls to sensitive endpoints from the same source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-28255 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-28255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.