Vulnerability Management

Metabase SQL injection vulnerability exploited in zero-day attacks

Cybersecurity Alert Critical System Vulnerability Detected

As noted by Bleeping Computer, a critical SQL injection vulnerability in Metabase, identified as a zero-day exploit, has been actively used to compromise customer instances, leading to data theft.

The vulnerability, affecting Metabase versions 1.58 and above, allows unauthenticated remote attackers to inject arbitrary SQL, potentially gaining administrator access. This access can enable attackers to alter configurations, steal stored credentials, and exfiltrate data. Metabase Cloud customers have been automatically patched, while self-hosted installations require manual updates to patched versions such as 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. Organizations unable to upgrade immediately can temporarily block the "/api/session/reset_password" endpoint.

Companies like Framework and Tally have confirmed that their Metabase instances were breached, resulting in the theft of customer information, including names, email addresses, and billing details. LexisNexis also reported a service disruption affecting its Metabase API due to a third-party vendor incident, though customer data exposure is unconfirmed.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds