PT-2026-99101 · Unknown · Openmetadata
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenMetadata versions prior to 2.0.3
Description
An issue exists in the
URLValidator.validateURL() function where DNS hostnames are not properly resolved and internal addresses are not correctly validated. This allows users with permissions to create or update EventSubscription to configure webhook destinations pointing to internal hosts. Consequently, the server can be induced to send requests to private networks and cloud metadata endpoints, with the returned HTTP status codes facilitating blind Server-Side Request Forgery (SSRF) probing, a technique used to confirm the existence of internal services without seeing the direct response body.Recommendations
Update OpenMetadata to version 2.0.3 or later.
Restrict the ability to create or update
EventSubscription to trusted administrators only.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openmetadata