CVE-2022-39358

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious request to the backend. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

History

28 Oct 2022, 16:04

Type Values Removed Values Added
CWE CWE-667
First Time Metabase
Metabase metabase
CPE cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-8qgm-9mj6-36h3 - (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-8qgm-9mj6-36h3 - Third Party Advisory

26 Oct 2022, 19:38

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-26 19:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-39358

Mitre link : CVE-2022-39358

CVE.ORG link : CVE-2022-39358


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-667

Improper Locking

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor