Security Advisory

CVE-2024-55238

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-04-17 00:00:00
Last updated 2025-04-17 19:15:12
Assigner mitre
CVSS score 7.1
State PUBLISHED

Description

OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.