Metabase

Metabase

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 18.05.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:50

Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Metabase didn't enforce that req...

  • EPSS 0.1%
  • Veröffentlicht 28.01.2023 02:15:07
  • Zuletzt bearbeitet 21.11.2024 07:46:34

Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This allows someone...

  • EPSS 0.27%
  • Veröffentlicht 28.01.2023 02:15:07
  • Zuletzt bearbeitet 21.11.2024 07:46:34

Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. Sandboxed users shouldn't be able to view data about other Metabase users anywhere in the Metabase applic...

  • EPSS 0.4%
  • Veröffentlicht 26.10.2022 19:15:15
  • Zuletzt bearbeitet 21.11.2024 07:18:07

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could pose a possible attack vector. This issue is patched in versions 0.44.5,...

  • EPSS 1.61%
  • Veröffentlicht 26.10.2022 19:15:14
  • Zuletzt bearbeitet 21.11.2024 07:18:07

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Execution (RCE), which can be abused by users able to write SQL queries on H2 ...

  • EPSS 0.16%
  • Veröffentlicht 26.10.2022 19:15:13
  • Zuletzt bearbeitet 21.11.2024 07:18:06

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going throug...

  • EPSS 0.21%
  • Veröffentlicht 26.10.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:18:06

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or priva...

  • EPSS 0.21%
  • Veröffentlicht 26.10.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:18:06

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious re...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 26.10.2022 18:15:11
  • Zuletzt bearbeitet 07.05.2025 14:15:38

The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.

  • EPSS 0.42%
  • Veröffentlicht 14.04.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:14

Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing ...