Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API
Vulnerability Description
Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Metabase 授权问题漏洞
Vulnerability Description
Metabase是美国Metabase公司开源的一个开源数据分析平台。 Metabase 0.63.1之前版本存在授权问题漏洞,该漏洞源于未对glossary API端点执行数据分析师权限检查,可能导致任何已认证用户通过POST、PUT和DELETE请求创建、修改和删除术语表条目,未经授权篡改业务术语数据。
CVSS Information
N/A
Vulnerability Type
N/A