Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required

Share:

Users of Metabase, a popular business intelligence and data visualization software package, are being advised to update to the latest version following the discovery of an extremely severe flaw that could result in pre-authenticated remote code execution on affected installations.

Tracked as CVE-2023-38646, the issue impacts open-source editions prior to 0.46.6.1 and Metabase Enterprise versions before 1.46.6.1.

An unauthenticated attacker can run arbitrary commands with the same privileges as the Metabase server on the server you are running Metabase on, Metabase said in an advisory released last week.

The issue has also been addressed in the following older versions –

0.45.4.1 and 1.45.4.1
0.44.7.1 and 1.44.7.1, and
0.43.7.2 and 1.43.7.2

While there is no evidence that the issue has been exploited in the wild, data gathered by the Shadowserver Foundation shows that 5,488 out of the total 6,936 Metabase instances are vulnerable as of July 26, 2023. A majority of the instances are located in the U.S., India, Germany, France, the U.K., Brazil, and Australia.

Assetnote, which claimed it discovered and reported the bug to Metabase, said the vulnerability is due to a JDBC connection issue in the API endpoint /api/setup/validate, enabling a malicious actor to obtain a reverse shell on the system by means of a specially crafted request that takes advantage of an SQL injection flaw in the H2 database driver.

Users who cannot apply the patches immediately are recommended to block requests to the /api/setup endpoint, isolate the Metabase instance from your production network, and monitor for suspicious requests to the endpoint in question.

 

(c) Thin

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:35 pm, Jul 2, 2025
weather icon 18°C
L: 17° | H: 19°
clear sky
Humidity: 46 %
Pressure: 1023 mb
Wind: 8 mph NNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 1%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:48 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
17° | 19°°C 0 mm 0% 11 mph 58 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 13 mph 62 % 1029 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
15° | 19°°C 1 mm 100% 11 mph 91 % 1021 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
15° | 22°°C 0.48 mm 48% 13 mph 88 % 1008 mb 0 mm/h
Mon Jul 07 10:00 pm
weather icon
13° | 17°°C 1 mm 100% 12 mph 89 % 1011 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 17°°C 0 mm 0% 9 mph 45 % 1023 mb 0 mm/h
Tomorrow 4:00 am
weather icon
12° | 14°°C 0 mm 0% 5 mph 54 % 1025 mb 0 mm/h
Tomorrow 7:00 am
weather icon
14° | 14°°C 0 mm 0% 5 mph 58 % 1028 mb 0 mm/h
Tomorrow 10:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 40 % 1028 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
22° | 22°°C 0 mm 0% 5 mph 29 % 1028 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
26° | 26°°C 0 mm 0% 6 mph 22 % 1026 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 11 mph 24 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 9 mph 37 % 1027 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,025.69
3.17%
Ethereum(ETH)
€2,202.83
7.34%
Tether(USDT)
€0.85
0.03%
XRP(XRP)
€1.92
3.33%
Solana(SOL)
€130.55
4.63%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.145784
7.95%
Shiba Inu(SHIB)
€0.000010
6.21%
Pepe(PEPE)
€0.000009
9.74%
Scroll to Top