DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDatahub
APPDatahub< 1.3.1.8
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2022-39366CRITICAL9.9PL ✓ten sam produkt
DataHub: Pominięcie weryfikacji podpisu JWT umożliwia auth bypass
CVE-2023-25557HIGH7.5ten sam produkt
DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or ...
CVE-2023-25559HIGH8.2ten sam produkt
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is ...
CVE-2023-25560HIGH8.2ten sam produkt
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new ac...
CVE-2026-44501MEDIUM4.3ten sam produkt
DataHub to open-source'owa platforma metadanych. Przed wersją 1.5.0.3 frontend DataHub (datahub-frontend-react...