A cryptominer campaign leveraged five vulnerabilities in OpenMetadata to infect environments.Kubernetes environments have come under attack in a campaign exploiting vulnerabilities in OpenMetadata, Microsoft revealed Wednesday.The Microsoft Threat Intelligence report described how attackers leveraged five recently disclosed bugs in the open-source metadata management platform to deploy cryptominers on Kubernetes clusters since the beginning of April.OpenMetadata enables metadata to be managed across different data sources in a central repository for metadata lineage; compromising the OpenMetadata workload can lead to lateral movement due to its connections to other services on the cluster. Five OpenMetadata vulnerabilities, including a critical improper authentication flaw and a critical code injection bug, were used in the campaign to gain initial access and achieve remote code execution (RCE) on the workloads. The vulnerabilities, which were first disclosed on March 15, are tracked as CVE-2024-28255, CVE-2024-28847, CVE-2024-28253, CVE-2024-28848 and CVE-2024-28254.The vulnerabilities affect OpenMetadata versions prior to 1.3.1, and administrators who run an OpenMetadata workload on their Kubernetes cluster should ensure the image is up-to-date. Administrators should also use strong authentication measures and replace default credentials if the platform is exposed to the internet, Microsoft said.
Cloud Security, Network Security, Threat Intelligence
Microsoft finds Kubernetes clusters targeted by OpenMetadata exploits

An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds