CVE-2022-39360

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase now blocks password reset for all users who use SSO for their Metabase login.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

History

28 Oct 2022, 16:29

Type Values Removed Values Added
CPE cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-287
References (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-gw4g-ww2m-v7vc - (CONFIRM) https://github.com/metabase/metabase/security/advisories/GHSA-gw4g-ww2m-v7vc - Third Party Advisory
References (MISC) https://github.com/metabase/metabase/commit/edadf7303c3b068609f57ca073e67885d5c98730 - (MISC) https://github.com/metabase/metabase/commit/edadf7303c3b068609f57ca073e67885d5c98730 - Patch, Third Party Advisory

26 Oct 2022, 19:38

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-26 19:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-39360

Mitre link : CVE-2022-39360

CVE.ORG link : CVE-2022-39360


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-287

Improper Authentication

CWE-304

Missing Critical Step in Authentication