OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.
CVE ID: CVE-2024-55238
CVSS Base Severity: HIGH
CVSS Base Score: 7.1
CVSS Vector: CVSS:3.1/AC:L/AV:N/A:N/C:H/I:L/PR:L/S:U/UI:N
Vendor: n/a
Product: n/a
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 4.67% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)