Metabase

Metabase

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 21.02.2026 07:57:50
  • Zuletzt bearbeitet 02.03.2026 15:38:28

Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. Durin...

  • EPSS 0.05%
  • Veröffentlicht 12.01.2026 22:36:35
  • Zuletzt bearbeitet 13.01.2026 14:03:18

Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. T...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 09.06.2025 20:00:19
  • Zuletzt bearbeitet 10.07.2025 16:26:17

A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possib...

  • EPSS 0.35%
  • Veröffentlicht 10.04.2025 14:40:53
  • Zuletzt bearbeitet 11.04.2025 15:39:52

Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not always purge ...

  • EPSS 0.46%
  • Veröffentlicht 28.03.2025 14:47:36
  • Zuletzt bearbeitet 28.03.2025 18:11:40

Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that a...

  • EPSS 0.11%
  • Veröffentlicht 24.02.2025 22:15:23
  • Zuletzt bearbeitet 28.02.2025 16:07:41

Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and 1.53.2 of Metabase Enterprise Edition, users with imp...

  • EPSS 0.21%
  • Veröffentlicht 16.12.2024 20:15:13
  • Zuletzt bearbeitet 16.12.2024 20:15:13

Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed users. This is fixed in 1.52.2.5. Users on 1.52.0 or 1.52....

  • EPSS 2.36%
  • Veröffentlicht 04.08.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:11:46

Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Meta...

  • EPSS 94.26%
  • Veröffentlicht 21.07.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:58

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0...

  • EPSS 0.15%
  • Veröffentlicht 18.05.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:50

Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Metabase didn't enforce that req...