CVE-2025-5895
- EPSS 0.54%
- Veröffentlicht 09.06.2025 20:00:19
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possib...
CVE-2025-32382
- EPSS 0.36%
- Veröffentlicht 10.04.2025 14:40:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not always purge ...
CVE-2025-30371
- EPSS 0.4%
- Veröffentlicht 28.03.2025 14:47:36
- Zuletzt bearbeitet 15.04.2026 00:35:42
Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that a...
CVE-2025-27141
- EPSS 0.35%
- Veröffentlicht 24.02.2025 22:15:23
- Zuletzt bearbeitet 28.02.2025 16:07:41
Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and 1.53.2 of Metabase Enterprise Edition, users with imp...
CVE-2024-55951
- EPSS 0.42%
- Veröffentlicht 16.12.2024 20:15:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed users. This is fixed in 1.52.2.5. Users on 1.52.0 or 1.52....
CVE-2023-37470
- EPSS 1.35%
- Veröffentlicht 04.08.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:46
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Meta...
CVE-2023-38646
- EPSS 98.68%
- Veröffentlicht 21.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:58
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0...
CVE-2023-32680
- EPSS 0.6%
- Veröffentlicht 18.05.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:03:50
Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Metabase didn't enforce that req...
CVE-2023-23629
- EPSS 0.38%
- Veröffentlicht 28.01.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 07:46:34
Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This allows someone...
CVE-2023-23628
- EPSS 0.44%
- Veröffentlicht 28.01.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 07:46:34
Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. Sandboxed users shouldn't be able to view data about other Metabase users anywhere in the Metabase applic...