漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Metabase vulnerable to circumvention of local link access protection in GeoJson endpoint
Vulnerability Description
Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that are using the GeoJson feature could be potentially impacted if their Metabase is colocated with other unsecured resources. This is fixed in v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Migrating to Metabase Cloud or redeploying Metabase in a dedicated subnet with strict outbound port controls is an available workaround.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
Metabase 后置链接漏洞
Vulnerability Description
Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase v0.52.16.4之前版本、v1.52.16.4之前版本、v0.53.8之前版本和v1.53.8之前版本存在后置链接漏洞,该漏洞源于GeoJson端点本地链接访问保护被绕过。
CVSS Information
N/A
Vulnerability Type
N/A