CVEFinder.io

CVE-2023-25559

⚠️ high
🔍 Scan for this CVE
Summary

DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the user the frontend is sending the request on behalf of. When the backends retrieves the header, its name is retrieved in a case-insensitive way. This case differential can be abused by an attacker to smuggle an X-DataHub-Actor header with different casing (eg: X-DATAHUB-ACTOR). Thi

Description

DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the user the frontend is sending the request on behalf of. When the backends retrieves the header, its name is retrieved in a case-insensitive way. This case differential can be abused by an attacker to smuggle an X-DataHub-Actor header with different casing (eg: X-DATAHUB-ACTOR). This issue may lead to an authorization bypass by allowing any user to impersonate the system user account and perform any actions on its behalf. This vulnerability was discovered and reported by the GitHub Security lab and is tracked as GHSL-2022-079.

CVSS Score
8.2
High
EPSS Score
0.1
Exploit Probability
Published Date
2023-02-11
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 79.2% of all 348,756 vulnerabilities in our database.

#72,535
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Mar 10, 2025
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2025-12-03
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-44501 🔶 medium 4.3 0.0 DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize... 2026-05-14
CVE-2026-25644 ⚠️ high 7.5 0.0 DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM a... 2026-02-06
CVE-2023-25557 ⚠️ high 7.5 0.6 DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL re... 2023-02-11
CVE-2023-25560 ⚠️ high 8.2 0.2 DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, ve... 2023-02-11
CVE-2023-25561 🔶 medium 5.7 0.2 DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Servic... 2023-02-11
CVE-2023-25562 🔶 medium 6.9 0.0 DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on ... 2023-02-11
These CVEs affect the same products