Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-41277
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GeoJSON URL validation can expose server files and environment variables to unauthorized users
Source: NVD (National Vulnerability Database)
Vulnerability Description
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Metabase 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase 中存在路径遍历漏洞,该漏洞源于产品的 admin->settings->maps->custom maps->add a map 操作缺少权限验证。攻击者可通过该漏洞获得敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
metabasemetabase < 0.40.5 -
II. Public POCs for CVE-2021-41277
#POC DescriptionSource LinkShenlong Link
1Metabase任意文件读取漏洞批量扫描工具https://github.com/Seals6/CVE-2021-41277POC Details
2PoC for CVE-2021-41277https://github.com/tahtaciburak/CVE-2021-41277POC Details
3 Metabase 任意文件读取https://github.com/Henry4E36/Metabase-cve-2021-41277POC Details
4MetaBase 任意文件读取漏洞 fofa批量pochttps://github.com/kap1ush0n/CVE-2021-41277POC Details
5simple program for exploit metabasehttps://github.com/z3n70/CVE-2021-41277POC Details
6plugin made for LeakiXhttps://github.com/kaizensecurity/CVE-2021-41277POC Details
7Nonehttps://github.com/Vulnmachines/Metabase_CVE-2021-41277POC Details
8Metabase GeoJSON map local file inclusionhttps://github.com/TheLastVvV/CVE-2021-41277POC Details
9Nonehttps://github.com/zer0yu/CVE-2021-41277POC Details
10CVE-2021-41277 can be extended to an SSRF https://github.com/sasukeourad/CVE-2021-41277_SSRFPOC Details
11It is a nmap script for metabase vulnerability (CVE-2021-41277)https://github.com/frknktlca/Metabase_Nmap_ScriptPOC Details
12MetaBase 任意文件读取https://github.com/Chen-ling-afk/CVE-2021-41277POC Details
13Nonehttps://github.com/RubXkuB/PoC-Metabase-CVE-2021-41277POC Details
14MetaBase 任意文件读取https://github.com/chengling-ing/CVE-2021-41277POC Details
15It is a nmap script for metabase vulnerability (CVE-2021-41277)https://github.com/grey-master-a/Metabase_Nmap_ScriptPOC Details
16Metabase is an open source data analytics platform. In affected versions a local file inclusion security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41277.yamlPOC Details
17Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Metabase%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20CVE-2021-41277.mdPOC Details
18Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Metabase%20geojson%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20CVE-2021-41277.mdPOC Details
19https://github.com/vulhub/vulhub/blob/master/metabase/CVE-2021-41277/README.mdPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-41277
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-41277

No comments yet


Leave a comment