OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.open-metadata:openmetadata-service(Maven) | 0 | N/A | N/A |
CVSS Metrics