Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-37470— Metabase vulnerable to remote code execution via POST /api/setup/validate API endpoint

Quick assessment

Affected
metabase metabase
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase存在代码注入漏洞,该漏洞源于允许攻击者在元数据库服务器上远程执行代码。受影响的产品和版本:Metabase 0.43.7.3之前版本,0.44.7.3之前版本,0.45.4.3之前版本,0.46.6.4之前版本,1.43.7.3之前版本,1.44.7.3之前版本,1.45.4.3之前版本,1.46.6.4之前版本。

CVSS 10.0 · Critical EPSS 1.35% · P70

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-37470

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Metabase vulnerable to remote code execution via POST /api/setup/validate API endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue is that one of the supported data warehouses (an embedded in-memory database H2), exposes a number of ways for a connection string to include code that is then executed by the process running the embedded database. Because Metabase allows users to connect to databases, this means that a user supplied string can be used to inject executable code. Metabase allows users to validate their connection string before adding a database (including on setup), and this validation API was the primary vector used as it can be called without validation. Versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4 fix this issue by removing the ability of users to add H2 databases entirely. As a workaround, it is possible to block these vulnerabilities at the network level by blocking the endpoints `POST /api/database`, `PUT /api/database/:id`, and `POST /api/setup/validateuntil`. Those who use H2 as a file-based database should migrate to SQLite.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5
Vulnerability Title
Metabase 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase存在代码注入漏洞,该漏洞源于允许攻击者在元数据库服务器上远程执行代码。受影响的产品和版本:Metabase 0.43.7.3之前版本,0.44.7.3之前版本,0.45.4.3之前版本,0.46.6.4之前版本,1.43.7.3之前版本,1.44.7.3之前版本,1.45.4.3之前版本,1.46.6.4之前版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
metabase metabase < 0.43.7.3 -

II. Public POCs for CVE-2023-37470

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-37470

请登录查看更多情报信息。

Vendor Advisories for CVE-2023-37470 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-37470

No comments yet


Leave a comment