Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HMetabase
APPMetabase1.55.0 – 1.58.15.1 (excl.)1.59.0 – 1.59.12 (excl.)1.60.0 – 1.60.6.3 (excl.)1.61.0 – 1.61.2 (excl.)
Related vulnerabilities
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database ...
Metabase – path traversal i odczyt lokalnych plików przez custom GeoJSON
RCE w Metabase poprzez podatny sterownik JDBC Snowflake
Metabase: RCE przez deserializację obiektów Java w zapytaniach H2
Metabase RCE przez złośliwy connection string bazy H2