CVE-2022-24854

Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows connecting multiple SQLite databases via the initial connection. If the attacker has SQL permissions to at least one SQLite database, then it can attach this database to a second database, and then it can query across all the tables. To be able to do that the attacker also needs to know the file path to the second database. Users are advised to upgrade as soon as possible. If you're unable to upgrade, you can modify your SQLIte connection strings to contain the url argument `?limit_attached=0`, which will disallow making connections to other SQLite databases. Only users making use of SQLite are affected.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

History

22 Apr 2022, 16:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CPE cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
References (MISC) https://www.sqlite.org/lang_attach.html - (MISC) https://www.sqlite.org/lang_attach.html - Third Party Advisory
References (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-vm79-xvmp-7329 - (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-vm79-xvmp-7329 - Release Notes, Third Party Advisory

14 Apr 2022, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-14 22:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-24854

Mitre link : CVE-2022-24854

CVE.ORG link : CVE-2022-24854


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere