CVE-2022-39359

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable `MB_CUSTOM_GEOJSON_ENABLED` was also added to disable custom GeoJSON completely (`true` by default).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

History

28 Oct 2022, 16:10

Type Values Removed Values Added
First Time Metabase
Metabase metabase
CPE cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
CWE CWE-601
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4 - (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4 - Third Party Advisory
References (MISC) https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771e - (MISC) https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771e - Patch, Third Party Advisory

26 Oct 2022, 19:38

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-26 19:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-39359

Mitre link : CVE-2022-39359

CVE.ORG link : CVE-2022-39359


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor