Bleepingcomputer
Critical SQL Injection Zero-Day in Metabase Leads to Data Breach
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical SQL injection vulnerability in Metabase versions 1.58 and above was exploited in zero-day attacks, compromising customer data. The vulnerability allows unauthenticated remote attackers to gain administrator access to Metabase instances, enabling them to alter configurations, steal credentials, and export data. Metabase has confirmed active exploitation of this flaw, which has not yet been assigned a CVE identifier but is rated Critical with a CVSS score of 10.0. Both Metabase Cloud and self-hosted installations are affected, with the company urging immediate upgrades for self-hosted users. Framework, a laptop manufacturer, reported that customer information was stolen due to this breach. Metabase has rolled out patches for Cloud customers and provided guidance for self-hosted users to mitigate the risk.
Key Points: • A critical SQL injection vulnerability in Metabase allows unauthorized access to customer data. • The flaw affects versions 1.58 and above, with active exploitation confirmed. • Metabase recommends immediate upgrades and has provided specific steps for self-hosted users.