CyberRota Analysis
AI-GeneratedMetabase versions 1.57.0 to 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4 are vulnerable to a file read vulnerability that allows attackers with access to configure a database connection to exploit unsafe JDBC parameters, potentially exposing sensitive files from the server's filesystem. This could lead to unauthorized access to sensitive data, making it critical for organizations using affected versions to prioritize upgrading to the patched releases. Users of Metabase, particularly those managing database connections, should take immediate action to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe JDBC parameters to a MySQL or MariaDB connection, causing the driver to read files from the Metabase host and expose the contents through queries against the connected database or through validation error messages. This issue is fixed in versions 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4.
Related CVEs
Other vulnerabilities affecting the same vendor(s)