关键信息 漏洞标题 It's possible to circumvent local link access protection in GeoJson endpoint 严重性 Low (2.1/10) 影响版本 Affected versions: <52.16.4, <53.8 修复版本 Patched versions: 52.16.4, 53.8 描述 Impact: Self-hosted Metabase instances using the Geojson feature could be impacted if colocated with other unsecured resources. 修复措施 Patches: Fixed in v0.52.16.4, v1.52.16.4, v0.53.8, v1.53.8 解决方案 Workarounds: Migrating to Metabase Cloud or redeploying Metabase in a dedicated subnet with strict outbound port controls. 检查是否受影响 Checking if you are impacted: Local reproduction is possible using dnsmasq to create local A records with multiple IPs, setting one of the IPs as a local link address, running a local http server or nc on that local IP HTTP port and retrying setting the Geojson address until the local server sees an incoming request. CVSS v4 基本指标 Exploitability Metrics - Attack Vector: Network - Attack Complexity: High - Attack Requirements: Present - Privileges Required: High - User interaction: None Vulnerable System Impact Metrics - Confidentiality: None - Integrity: None - Availability: None Subsequent System Impact Metrics - Confidentiality: Low - Integrity: None - Availability: None CVE ID CVE-2025-30371 弱点 Weaknesses: No CWEs