logo

Active Kubernetes RCE Attack Relies on Known OpenMetadata Vulns

ID: 95506a4b-19be-521d-b1f5-b9d542f16b94

STIX ID: report--95506a4b-19be-521d-b1f5-b9d542f16b94

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-04-17

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Microsoft Threat Intelligence reports that multiple vulnerabilities (CVE-2024-28255, CVE-2024-28847, CVE-2024-28253, CVE-2024-28848, CVE-2024-28254) in OpenMetadata versions prior to v1.3.1 have been actively exploited since early April to achieve remote code execution on internet-exposed Kubernetes workloads; attackers have used compromised clusters for cryptocurrency mining and could potentially conduct lateral movement. OpenMetadata and Microsoft advise applying patches (fixed in Jan/March releases), enforcing strong authentication, and resetting default credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.