Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required

Teilen:

Users of Metabase, a popular business intelligence and data visualization software package, are being advised to update to the latest version following the discovery of an extremely severe flaw that could result in pre-authenticated remote code execution on affected installations.

Tracked as CVE-2023-38646, the issue impacts open-source editions prior to 0.46.6.1 and Metabase Enterprise versions before 1.46.6.1.

An unauthenticated attacker can run arbitrary commands with the same privileges as the Metabase server on the server you are running Metabase on, Metabase said in an advisory released last week.

The issue has also been addressed in the following older versions –

0.45.4.1 and 1.45.4.1
0.44.7.1 and 1.44.7.1, and
0.43.7.2 and 1.43.7.2

While there is no evidence that the issue has been exploited in the wild, data gathered by the Shadowserver Foundation shows that 5,488 out of the total 6,936 Metabase instances are vulnerable as of July 26, 2023. A majority of the instances are located in the U.S., India, Germany, France, the U.K., Brazil, and Australia.

Assetnote, which claimed it discovered and reported the bug to Metabase, said the vulnerability is due to a JDBC connection issue in the API endpoint /api/setup/validate, enabling a malicious actor to obtain a reverse shell on the system by means of a specially crafted request that takes advantage of an SQL injection flaw in the H2 database driver.

Users who cannot apply the patches immediately are recommended to block requests to the /api/setup endpoint, isolate the Metabase instance from your production network, and monitor for suspicious requests to the endpoint in question.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:05 am, Juni 1, 2025
Wetter-Symbol 15°C
L: 14° | H: 16°
klarer Himmel
Luftfeuchtigkeit: 78 %
Druck: 1015 mb
Wind: 5 mph NNW
Windböe: 10 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 16°°C 0.2 mm 20% 15 mph 79 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 12 mph 81 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 17 mph 89 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 17°°C 0.61 mm 61% 13 mph 79 % 1011 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 15 mph 96 % 1010 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
14° | 15°°C 0 mm 0% 7 mph 79 % 1014 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 9 mph 76 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 46 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 37 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 11 mph 55 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 81 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,083.41
0.43%
Ethereum(ETH)
€2,223.82
-0.10%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.91
1.74%
Solana(SOL)
€137.68
0.01%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.168906
-0.40%
Shiba Inu(SHIB)
€0.000011
1.14%
Pepe(PEPE)
€0.000011
1.54%
Peanut das Eichhörnchen(PNUT)
€0.229763
5.30%
Nach oben scrollen