CVE-2022-39359
Last modified
CVE-2022-39359 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable `MB_CUSTOM_GEOJSON_ENABLED` was also added to disable custom GeoJSON completely (`true` by default).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metabase | Metabase | >= 0.41.0, < 0.41.9 |
| Metabase | Metabase | >= 0.42.0, < 0.42.6 |
| Metabase | Metabase | >= 0.43.0, < 0.43.7 |
| Metabase | Metabase | >= 0.44.0, < 0.44.5 |
| Metabase | Metabase | >= 1.41.0, < 1.41.9 |
| Metabase | Metabase | >= 1.42.0, < 1.42.6 |
| Metabase | Metabase | >= 1.43.0, < 1.43.7 |
| Metabase | Metabase | >= 1.44.0, < 1.44.5 |
References
- https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771ePatch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4Third Party Advisory
- https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771ePatch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39359?
How severe is CVE-2022-39359?
How do I fix CVE-2022-39359?
Are you affected by CVE-2022-39359?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
