Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable `MB_CUSTOM_GEOJSON_ENABLED` was also added to disable custom GeoJSON completely (`true` by default).
References
Link | Resource |
---|---|
https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771e | Patch Third Party Advisory |
https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
28 Oct 2022, 16:10
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4 - Third Party Advisory | |
References | (MISC) https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771e - Patch, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CWE | CWE-601 | |
CPE | cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* |
26 Oct 2022, 19:38
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-10-26 19:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-39359
Mitre link : CVE-2022-39359
CVE.ORG link : CVE-2022-39359
JSON object : View
Products Affected
metabase
- metabase