CVE-2022-39360
Last modified
CVE-2022-39360 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase now blocks password reset for all users who use SSO for their Metabase login.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metabase | Metabase | >= 0.41.0, < 0.41.9 |
| Metabase | Metabase | >= 0.42.0, < 0.42.6 |
| Metabase | Metabase | >= 0.43.0, < 0.43.7 |
| Metabase | Metabase | >= 0.44.0, < 0.44.5 |
| Metabase | Metabase | >= 1.41.0, < 1.41.9 |
| Metabase | Metabase | >= 1.42.0, < 1.42.6 |
| Metabase | Metabase | >= 1.43.0, < 1.43.7 |
| Metabase | Metabase | >= 1.44.0, < 1.44.5 |
References
- https://github.com/metabase/metabase/commit/edadf7303c3b068609f57ca073e67885d5c98730Patch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-gw4g-ww2m-v7vcThird Party Advisory
- https://github.com/metabase/metabase/commit/edadf7303c3b068609f57ca073e67885d5c98730Patch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-gw4g-ww2m-v7vcThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39360?
How severe is CVE-2022-39360?
How do I fix CVE-2022-39360?
Are you affected by CVE-2022-39360?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
