CVE-2022-39358

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious request to the backend. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

History

28 Oct 2022, 16:04

Type Values Removed Values Added
CWE CWE-667
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
References (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-8qgm-9mj6-36h3 - (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-8qgm-9mj6-36h3 - Third Party Advisory

26 Oct 2022, 19:38

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-26 19:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-39358

Mitre link : CVE-2022-39358

CVE.ORG link : CVE-2022-39358


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-667

Improper Locking

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor