CVE-2022-39366
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service authentication is enabled. This vulnerability occurs because the `StatelessTokenService` of the Metadata service uses the `parse` method of `io.jsonwebtoken.JwtParser`, which does not perform a verification of the cryptographic token signature. This means that JWTs are accepted regardless of the used algorithm. This issue may lead to an authentication bypass. Version 0.8.45 contains a patch for the issue. There are no known workarounds.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
- EPSS probability
- 0.04%
- CWE
- CWE-303, CWE-287
- Published
- 2022-10-28
- Last modified
- 2026-03-13
Affected products
- datahub-project datahub
Weakness type
Related vulnerabilities
- CVE-2024-7593 — Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
- CVE-2022-20695 — Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability
- CVE-2025-13390 — WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
- CVE-2024-4985 — An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sig
- CVE-2025-66489 — Cal.com Authentication Bypass via bad TOTP + password checks
- CVE-2025-12421 — Account Takeover via Code Exchange Endpoint
- CVE-2025-12419 — Account takeover on OAuth/OpenID-enabled servers
- CVE-2024-4332 — Improper Authentication in Tripwire Enterprise 9.1.0 APIs