Active Kubernetes RCE Attack Relies on Known OpenMetadata Vulns
ID: 95506a4b-19be-521d-b1f5-b9d542f16b94
STIX ID: report--95506a4b-19be-521d-b1f5-b9d542f16b94
Feed Name: Dark Reading
Date Published: 2024-04-17
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Microsoft Threat Intelligence reports that multiple vulnerabilities (CVE-2024-28255, CVE-2024-28847, CVE-2024-28253, CVE-2024-28848, CVE-2024-28254) in OpenMetadata versions prior to v1.3.1 have been actively exploited since early April to achieve remote code execution on internet-exposed Kubernetes workloads; attackers have used compromised clusters for cryptocurrency mining and could potentially conduct lateral movement. OpenMetadata and Microsoft advise applying patches (fixed in Jan/March releases), enforcing strong authentication, and resetting default credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
