CVEFinder.io

CVE-2023-25562

🔶 medium
🔍 Scan for this CVE
Summary

DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on new sign-in events and not on logout events. Any authentication checks using the `AuthUtils.hasValidSessionCookie()` method could be bypassed by using a cookie from a logged out session, as a result any logged out session cookie may be accepted as valid and therefore lead to an authentication bypass to the system. Users are advised to upgrade. There are no known workarounds for

Description

DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on new sign-in events and not on logout events. Any authentication checks using the `AuthUtils.hasValidSessionCookie()` method could be bypassed by using a cookie from a logged out session, as a result any logged out session cookie may be accepted as valid and therefore lead to an authentication bypass to the system. Users are advised to upgrade. There are no known workarounds for this issue. This vulnerability was discovered and reported by the GitHub Security lab and is tracked as GHSL-2022-083.

CVSS Score
6.9
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2023-02-11
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 50.0% of all 348,756 vulnerabilities in our database.

#174,446
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Mar 10, 2025
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2025-12-03
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-44501 🔶 medium 4.3 0.0 DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize... 2026-05-14
CVE-2026-25644 ⚠️ high 7.5 0.0 DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM a... 2026-02-06
CVE-2023-25557 ⚠️ high 7.5 0.6 DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL re... 2023-02-11
CVE-2023-25559 ⚠️ high 8.2 0.1 DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the defaul... 2023-02-11
CVE-2023-25560 ⚠️ high 8.2 0.2 DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, ve... 2023-02-11
CVE-2023-25561 🔶 medium 5.7 0.2 DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Servic... 2023-02-11
These CVEs affect the same products