Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9vmh-whc4-7phg | OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users |
Mon, 08 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-metadata
Open-metadata openmetadata |
|
| Vendors & Products |
Open-metadata
Open-metadata openmetadata |
Mon, 08 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in request.connection.config.password and the ingestion bot JWT in openMetadataServerConnection.securityConfig.jwtToken. The leaked ingestion-bot token can then be reused as Authorization: Bearer <jwt> to access sensitive service APIs with bot-level privileges. This issue has been patched in version 1.12.4. | |
| Title | OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T18:24:35.488Z
Reserved: 2026-05-14T18:06:06.810Z
Link: CVE-2026-46481
Updated: 2026-06-08T18:24:18.457Z
Status : Deferred
Published: 2026-06-08T17:16:51.847
Modified: 2026-06-09T15:25:56.860
Link: CVE-2026-46481
No data.
OpenCVE Enrichment
Updated: 2026-06-08T19:45:31Z
Github GHSA