CVEFinder.io

CVE-2023-25557

⚠️ high
🔍 Scan for this CVE
Summary

DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to the backend. The goal of this proxy is to perform authentication if needed and forward HTTP requests to the DataHub Metadata Store (GMS). It has been discovered that the proxy does not adequately construct the URL when forwarding data to GMS, allowing external users to reroute requests from the DataHub Frontend to any arbitrary hosts. As a result attackers may be able

Description

DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to the backend. The goal of this proxy is to perform authentication if needed and forward HTTP requests to the DataHub Metadata Store (GMS). It has been discovered that the proxy does not adequately construct the URL when forwarding data to GMS, allowing external users to reroute requests from the DataHub Frontend to any arbitrary hosts. As a result attackers may be able to reroute a request from originating from the frontend proxy to any other server and return the result. This vulnerability was discovered and reported by the GitHub Security lab and is tracked as GHSL-2022-076.

CVSS Score
7.5
High
EPSS Score
0.6
Exploit Probability
Published Date
2023-02-11
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.0% of all 348,756 vulnerabilities in our database.

#111,664
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Mar 10, 2025
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-12-03
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-44501 🔶 medium 4.3 0.0 DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize... 2026-05-14
CVE-2026-25644 ⚠️ high 7.5 0.0 DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM a... 2026-02-06
CVE-2023-25559 ⚠️ high 8.2 0.1 DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the defaul... 2023-02-11
CVE-2023-25560 ⚠️ high 8.2 0.2 DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, ve... 2023-02-11
CVE-2023-25561 🔶 medium 5.7 0.2 DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Servic... 2023-02-11
CVE-2023-25562 🔶 medium 6.9 0.0 DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on ... 2023-02-11
These CVEs affect the same products