Home/Product/datahub
Product

datahub

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44501
< 1.5.0.3
DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker
4.3MEDIUM
CVE-2026-25644
< 1.3.1.8
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack thro
7.5HIGH
CVE-2024-29037
>= 0.1.143 and < 0.2.182
datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Starting in v
9.1CRITICAL
CVE-2024-22409
< 0.12.1
DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, o
7.5HIGH
CVE-2023-47640
< 0.11.1
DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a SHA-1 HMAC
6.4MEDIUM
CVE-2023-47629
< 0.12.1
DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users
7.1HIGH
CVE-2023-47628
< 0.12.1
DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default settings fo
4.2MEDIUM
CVE-2023-25562
< 0.8.45
DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on new sign-i
6.9MEDIUM
CVE-2023-25561
< 0.8.45
DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Service (JAAS) a
5.7MEDIUM
CVE-2023-25560
< 0.8.45
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, verifying cr
8.2HIGH
CVE-2023-25559
< 0.8.45
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configur
8.2HIGH
CVE-2023-25558
< 0.9.5
DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the
7.5HIGH
CVE-2023-25557
< 0.8.45
DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to
7.5HIGH
CVE-2022-39366
< 0.8.45
DataHub is an open-source metadata platform. Prior to version 0.8.45, the StatelessTokenService of the DataHub metadata service
9.9CRITICAL
CVE-2022-0955
< 1.2.4
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.
4.8MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin