QID 730322
Date Published: 2022-01-03
QID 730322: Metabase Local File Inclusion (LFI) Vulnerability
Metabase is an open source business intelligence tool. It lets you ask questions about your data, and displays answers in formats that make sense, whether that's a bar graph or a detailed table.
CVE-2021-41277: In affected versions a security issue has been discovered with the custom GeoJSON map support and potential local file inclusion (including environment variables).
Affected Versions:
Metabase versions x.40.0, x.40.1, x.40.2, x.40.3, x.40.4
Detection logic (Unauthenticated):
Request to include local default files using endpoint "/api/geojson?url=".
Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to include local files and read sensitive files of the target system.
Solution
Vendor has released fix to address this vulnerability. Refer to Metabase Advisory for further updates.
Vendor References
- Metabase Advisory -
github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr
CVEs related to QID 730322
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Metabase Advisory |
|