CVE-2022-39362
Last modified
CVE-2022-39362 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could pose a possible attack vector. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could pose a possible attack vector. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer automatically executes ad-hoc native queries. Now the native editor shows the query and gives the user the option to manually run the query if they want.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metabase | Metabase | >= 0.41.0, < 0.41.9 |
| Metabase | Metabase | >= 0.42.0, < 0.42.6 |
| Metabase | Metabase | >= 0.43.0, < 0.43.7 |
| Metabase | Metabase | >= 0.44.0, < 0.44.5 |
| Metabase | Metabase | >= 1.41.0, < 1.41.9 |
| Metabase | Metabase | >= 1.42.0, < 1.42.6 |
| Metabase | Metabase | >= 1.43.0, < 1.43.7 |
| Metabase | Metabase | >= 1.44.0, < 1.44.5 |
References
- https://github.com/metabase/metabase/commit/b7c6bb905a9187347cfc9035443b514713027a5cPatch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-93wj-fgjg-r238Third Party Advisory
- https://github.com/metabase/metabase/commit/b7c6bb905a9187347cfc9035443b514713027a5cPatch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-93wj-fgjg-r238Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39362?
How severe is CVE-2022-39362?
How do I fix CVE-2022-39362?
Are you affected by CVE-2022-39362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
