<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:31:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02655</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02655</link>
      <description>bdu:2024-02655</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02655</guid>
    </item>
    <item>
      <title>EUVD-2026-160366</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-160366</link>
      <description>EUVD-2026-160366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-160366</guid>
    </item>
    <item>
      <title>fkie_cve-2024-28253</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28253</link>
      <description>&lt;p&gt;OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called from `EntityRepository.prepareInternal()` which, in turn, gets called from `EntityResource.createOrUpdate()`. Note that even though there is an authorization check (`authorizer.authorize()`), it gets called after `prepareInternal()` gets called and therefore after the SpEL expression has been evaluated. In order to reach this method, an attacker can send a PUT request to `/api/v1/policies` which gets handled by `PolicyResource.createOrUpdate()`. This vulnerability was discovered with the help of CodeQL&amp;#39;s Expression language injection (Spring) query and is also tracked as `GHSL-2023-252`. This issue may lead to Remote Code Execution and has been addressed in version 1.3.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`. `prepare()` is called from `EntityRepository.prepareInternal()` which, in turn, gets called from `EntityResource.createOrUpdate()`. Note that even though there is an authorization check (`authorizer.authorize()`), it gets called after `prepareInternal()` gets called and therefore after the SpEL expression has been evaluated. In order to reach this method, an attacker can send a PUT request to `/api/v1/policies` which gets handled by `PolicyResource.createOrUpdate()`. This vulnerability was discovered with the help of CodeQL&amp;#39;s Expression language injection (Spring) query and is also tracked as `GHSL-2023-252`. This issue may lead to Remote Code Execution and has been addressed in version 1.3.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-28253</guid>
    </item>
    <item>
      <title>GHSA-7vf4-x5m2-r6gr — OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7vf4-x5m2-r6gr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.open-metadata:openmetadata-service&lt;/p&gt;
&lt;p&gt;### SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)&lt;/p&gt;
&lt;p&gt;**Please note, only authenticated users have access to PUT / POST APIS for /api/v1/policies. Non authenticated users will not be able to access these APIs to exploit the vulnerability**&lt;/p&gt;
&lt;p&gt;`CompiledRule::validateExpression` is also called from [`PolicyRepository.prepare`](https://github.com/open-metadata/OpenMetadata/blob/main/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/PolicyRepository.java#L113)&lt;/p&gt;
&lt;p&gt;```java
  @Override
  public void prepare(Policy policy, boolean update) {
    validateRules(policy);
  }
  ...
  public void validateRules(Policy policy) {
    List&amp;lt;Rule&amp;gt; rules = policy.getRules();
    if (nullOrEmpty(rules)) {
      throw new IllegalArgumentException(CatalogExceptionMessage.EMPTY_RULES_IN_POLICY);
    }&lt;/p&gt;
&lt;p&gt;// Validate all the expressions in the rule
    for (Rule rule : rules) {
      CompiledRule.validateExpression(rule.getCondition(), Boolean.class);
      rule.getResources().sort(String.CASE_INSENSITIVE_ORDER);
      rule.getOperations().sort(Comparator.comparing(MetadataOperation::value));&lt;/p&gt;
&lt;p&gt;// Remove redundant resources
      rule.setResources(filterRedundantResources(rule.getResources()));&lt;/p&gt;
&lt;p&gt;// Remove redundant operations
      rule.setOperations(filterRedundantOperations(rule.getOperations()));
    }
    rules.sort(Comparator.comparing(Rule::getName));
  }
```&lt;/p&gt;
&lt;p&gt;`prepare()` is called from [`EntityRepository.prepareInternal()`](https://github.com/open-metadata/O…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.open-metadata:openmetadata-service&lt;/p&gt;
&lt;p&gt;### SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)&lt;/p&gt;
&lt;p&gt;**Please note, only authenticated users have access to PUT / POST APIS for /api/v1/policies. Non authenticated users will not be able to access these APIs to exploit the vulnerability**&lt;/p&gt;
&lt;p&gt;`CompiledRule::validateExpression` is also called from [`PolicyRepository.prepare`](https://github.com/open-metadata/OpenMetadata/blob/main/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/PolicyRepository.java#L113)&lt;/p&gt;
&lt;p&gt;```java
  @Override
  public void prepare(Policy policy, boolean update) {
    validateRules(policy);
  }
  ...
  public void validateRules(Policy policy) {
    List&amp;lt;Rule&amp;gt; rules = policy.getRules();
    if (nullOrEmpty(rules)) {
      throw new IllegalArgumentException(CatalogExceptionMessage.EMPTY_RULES_IN_POLICY);
    }&lt;/p&gt;
&lt;p&gt;// Validate all the expressions in the rule
    for (Rule rule : rules) {
      CompiledRule.validateExpression(rule.getCondition(), Boolean.class);
      rule.getResources().sort(String.CASE_INSENSITIVE_ORDER);
      rule.getOperations().sort(Comparator.comparing(MetadataOperation::value));&lt;/p&gt;
&lt;p&gt;// Remove redundant resources
      rule.setResources(filterRedundantResources(rule.getResources()));&lt;/p&gt;
&lt;p&gt;// Remove redundant operations
      rule.setOperations(filterRedundantOperations(rule.getOperations()));
    }
    rules.sort(Comparator.comparing(Rule::getName));
  }
```&lt;/p&gt;
&lt;p&gt;`prepare()` is called from [`EntityRepository.prepareInternal()`](https://github.com/open-metadata/O…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7vf4-x5m2-r6gr</guid>
    </item>
    <item>
      <title>gsd-2024-28253</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-28253</link>
      <description>gsd-2024-28253</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-28253</guid>
    </item>
  </channel>
</rss>
