Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Metabase 代码问题漏洞
Vulnerability Description
Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase 44.5之前版本存在安全漏洞,该漏洞源于/api/geojson端点的url参数可用于执行服务器端请求伪造攻击,利用301和302重定向可以绕过以前实施的黑名单。
CVSS Information
N/A
Vulnerability Type
N/A