Impact
Amundsen frontend releases through version 4.3.0 render table, dashboard, and feature descriptions using dangerouslySetInnerHTML without any HTML sanitization. The stored input fields are populated from the metadata service or Elasticsearch, allowing an attacker to place malicious markup such as an image tag with an onerror handler into a description. When a user views a search result that includes the injected markup, the browser executes the attacker‑supplied JavaScript in the context of the Amundsen application, granting the attacker the ability to run arbitrary code, steal session cookies, or perform other client‑side attacks.
Affected Systems
The vulnerability impacts the Amundsen Frontend component (amundsen-io/amundsen-frontend) for all deployments using version 4.3.0 or earlier. No other vendors or products are listed as affected.
Risk and Exploitability
8.3, indicating high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Attackers can exploit the flaw by inserting malicious content into a description field via the metadata service or Elasticsearch, content is at risk of executing arbitrary JavaScript. Because the exploit path requires the attacker to insert data into the description field, it is likely that the vulnerability is exploitable in environments where the metadata service or Elasticsearch is accessible to the attacker and description inputs are not strictly controlled.
OpenCVE Enrichment