QID 730322

Date Published: 2022-01-03

QID 730322: Metabase Local File Inclusion (LFI) Vulnerability

Metabase is an open source business intelligence tool. It lets you ask questions about your data, and displays answers in formats that make sense, whether that's a bar graph or a detailed table.

CVE-2021-41277: In affected versions a security issue has been discovered with the custom GeoJSON map support and potential local file inclusion (including environment variables).

Affected Versions:
Metabase versions x.40.0, x.40.1, x.40.2, x.40.3, x.40.4

Detection logic (Unauthenticated):
Request to include local default files using endpoint "/api/geojson?url=".

Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to include local files and read sensitive files of the target system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released fix to address this vulnerability. Refer to Metabase Advisory for further updates.

    CVEs related to QID 730322

    Software Advisories
    Advisory ID Software Component Link
    Metabase Advisory URL Logo github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr