DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDatahub
APPDatahub< 1.3.1.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-39366CRITICAL9.9PL ✓same product
DataHub: Pominięcie weryfikacji podpisu JWT umożliwia auth bypass
CVE-2023-25557HIGH7.5same product
DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or ...
CVE-2023-25559HIGH8.2same product
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is ...
CVE-2023-25560HIGH8.2same product
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new ac...
CVE-2026-44501MEDIUM4.3same product
DataHub to open-source'owa platforma metadanych. Przed wersją 1.5.0.3 frontend DataHub (datahub-frontend-react...