Metabase is susceptible to remote code execution due to an incomplete patch in Apache Log4j 2.15.0 in certain non-default configurations. A remote attacker can pass malicious data and perform a denial of service attack, exfiltrate data, or execute arbitrary code.
id: metabase-log4j
info:
name: Metabase - Remote Code Execution (Apache Log4j)
author: Dhiyanes
...