Metabase patches CVSS 10.0 SQL injection zero-day exploited before disclosure
Metabase has disclosed a critical unauthenticated SQL injection vulnerability in its business intelligence platform, rated CVSS 10.0, that was actively exploited in the wild before the patch was released. The flaw allows remote attackers without any credentials to inject SQL into the Metabase application database and grant themselves administrator access. Because Metabase holds stored credentials to connected data warehouses and production databases, a successful compromise effectively exposes all linked data sources. Six version branches from 1.58 onwards are affected, and self-hosted users must manually apply the exact fixed build for their branch, as Metabase Cloud instances have already been updated by the vendor. As a temporary workaround, administrators who cannot patch immediately are advised to block the /api/session/reset_password endpoint at their reverse proxy or WAF.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in