Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

A maximum-severity security vulnerability affecting Metabase’s business intelligence and data visualization software package has been exploited in the wild as a zero-day, the company has warned.

An unauthenticated remote attacker can acquire administrator access to the instance by injecting arbitrary SQL into the Metabase application database thanks to the vulnerability (CVSS score: 10.0), which lacks a CVE name.

Equipped with elevated access, the attacker can read any data accessible thru those connections, export data, alter the application configuration, and steal stored passwords for the associated databases. In an advisory, Metabase stated, We recently discovered that someone used an unknown (‘0-day’) security vulnerability in versions 1.58 and above to attack Metabase Cloud.

Instances of Metabase Cloud have already been updated to the most recent version. It is recommended that users of self-hosted versions install security updates issued by Metabase right away. The versions listed below are impacted:

= x.58.0, < x.58.23 (Fixed in x.58.24)
= x.59.0, < x.59.20 (Fixed in x.59.21)
= x.60.0, < x.60.16 (Fixed in x.60.17)
= x.61.0, < x.61.10 (Fixed in x.61.11)
= x.62.0, < x.62.8 (Fixed in x.62.9)
= x.63.0, < x.63.3 (Fixed in x.63.5)

Blocking the “/api/session/reset_password” API is recommended as a temporary workaround until the improvements can be implemented. Customers who have public access to their read more about Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *