# GitHub Security Lab audited DataHub: Here's what they found

DevFeed: [GitHub Security Lab audited DataHub: Here's what they found](<https://devfeed.tech/articles/github-security-lab-audited-datahub-here-s-what-they-found-68073.md>)

Original publisher: [Read original article](<https://github.blog/security/vulnerability-research/github-security-lab-audited-datahub-heres-what-they-found/>)

Author: Alvaro Munoz

Published: 2023-03-03T19:53:01Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authentication-bypass](<https://devfeed.tech/tags/authentication-bypass.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [github-security](<https://devfeed.tech/tags/github-security.md>), [github-security-lab](<https://devfeed.tech/tags/github-security-lab.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

## AI overview

The GitHub Security Lab audited DataHub, an open source metadata platform, and found vulnerabilities in authentication, authorization, deserialization, and query handling. The article explains how the findings could enable authentication or authorization bypasses, data exposure, and other attacks, and describes fixes and disclosure to the DataHub team.

## Source excerpt

The GitHub Security Lab audited DataHub, an open source metadata platform, and discovered several vulnerabilities in the platform's authentication and authorization modules. These vulnerabilities could have enabled an attacker to bypass authentication and gain access to sensitive data stored on the platform.