Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase 存在安全漏洞,该漏洞源于单点登录 (SSO) 用户能够在 Metabase 上重置密码,这可以允许用户在不通过 SSO IdP 的情况下进行访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39361 | 8.8 HIGH | Metabase vulnerable to Remote Code Execution via H2 |
| CVE-2022-39362 | 8.8 HIGH | Metabase vulnerable to arbitrary SQL execution from queryhash |
| CVE-2022-39358 | 6.5 MEDIUM | Metabase vulnerable to circumvention of Locked parameter in Signed Embedding |
| CVE-2022-39359 | 6.5 MEDIUM | Metabase's GeoJSON validation doesn't prevent redirects to blocked URLs |
No comments yet