6.5

CVE-2022-39359

Metabase's GeoJSON validation doesn't prevent redirects to blocked URLs

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable `MB_CUSTOM_GEOJSON_ENABLED` was also added to disable custom GeoJSON completely (`true` by default).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MetabaseMetabase Version >= 0.41.0 < 0.41.9
MetabaseMetabase Version >= 0.42.0 < 0.42.6
MetabaseMetabase Version >= 0.43.0 < 0.43.7
MetabaseMetabase Version >= 0.44.0 < 0.44.5
MetabaseMetabase Version >= 1.41.0 < 1.41.9
MetabaseMetabase Version >= 1.42.0 < 1.42.6
MetabaseMetabase Version >= 1.43.0 < 1.43.7
MetabaseMetabase Version >= 1.44.0 < 1.44.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.419
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771e
Patch
Third Party Advisory
https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4
Third Party Advisory