CVE-2023-23628
Last modified
CVE-2023-23628 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. Sandboxed users shouldn't be able to view data about other Metabase users anywhere in the Metabase application. However, when a sandbox user views the settings for a dashboard subscription, and another user has added users to that subscription, the sandboxed user is able to view the list of recipients for that subscription. This issue is patched in versions 0.43.7.1, 1.43.7.1, 0.44.6.1, 1.44.6.1, 0.45.2.1, and 1.45.2.1. There are no workarounds.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metabase | Metabase | < 0.43.7.1 |
| Metabase | Metabase | >= 0.44.0, < 0.44.6.1 |
| Metabase | Metabase | >= 0.45.0, < 0.45.2.1 |
| Metabase | Metabase | >= 1.0.0, < 1.43.7.1 |
| Metabase | Metabase | >= 1.44.0, < 1.44.6.1 |
| Metabase | Metabase | >= 1.45.0, < 1.45.2.1 |
References
- https://github.com/metabase/metabase/security/advisories/GHSA-492f-qxr3-9rrvThird Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-492f-qxr3-9rrvThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23628?
How severe is CVE-2023-23628?
How do I fix CVE-2023-23628?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-23622Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2023-23623Electron is a framework which lets you write cross-platform …9.8
- CVE-2023-23624Discourse is an open-source discussion platform. Prior to ve…5.3
- CVE-2023-23625go-unixfs is an implementation of a unix-like filesystem on …7.5
- CVE-2023-23626go-bitfield is a simple bitfield package for the go language…7.5
- CVE-2023-23627Sanitize is an allowlist-based HTML and CSS sanitizer. Versi…6.1
- CVE-2023-23629Metabase is an open source data analytics platform. Affected…6.3
- CVE-2023-2363A vulnerability, which was classified as critical, has been …9.8
- CVE-2023-23630Eta is an embedded JS templating engine that works inside No…6.1
- CVE-2023-23631github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that…7.5
- CVE-2023-23632BeyondTrust Privileged Remote Access (PRA) versions 22.2.x t…7.8
- CVE-2023-23634SQL Injection vulnerability in Documize version 5.4.2, allow…9.8
Are you affected by CVE-2023-23628?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
