Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
A maximum-severity security vulnerability affecting Metabase's business intelligence and data visualization software package has been exploited in the wild as a zero-day, the company has warned.
An unauthenticated remote attacker can acquire administrator access to the instance by injecting arbitrary SQL into the Metabase application database thanks to the vulnerability (CVSS score: 10.0), which lacks a CVE name.
Equipped with elevated access, the attacker can read any data accessible thru those connections, export data, alter the application configuration, and steal stored passwords for the associated databases. In an advisory, Metabase stated, We recently discovered that someone used an unknown ('0-day') security vulnerability in versions 1.58 and above to attack Metabase Cloud.
...

