CVE-2022-39362
Metabase vulnerable to arbitrary SQL execution from queryhash
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could pose a possible attack vector. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer automatically executes ad-hoc native queries. Now the native editor shows the query and gives the user the option to manually run the query if they want.
Metabase es un software de visualización de datos. En versiones anteriores a 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9 y 1.41.9, eran auto ejecutadas las consultas SQL no guardadas, lo que podía suponer un posible vector de ataque. Este problema ha sido corregido en versiones 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9 y 1.41.9. Metabase ya no ejecuta automáticamente las consultas nativas ad hoc. Ahora el editor nativo muestra la consulta y da al usuario la opción de ejecutarla manualmente si lo desea
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-02 CVE Reserved
- 2022-10-26 CVE Published
- 2024-05-18 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-356: Product UI does not Warn User of Unsafe Actions
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/metabase/metabase/security/advisories/GHSA-93wj-fgjg-r238 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/metabase/metabase/commit/b7c6bb905a9187347cfc9035443b514713027a5c | 2022-10-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 0.41.0 < 0.41.9 Search vendor "Metabase" for product "Metabase" and version " >= 0.41.0 < 0.41.9" | - |
Affected
| ||||||
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 0.42.0 < 0.42.6 Search vendor "Metabase" for product "Metabase" and version " >= 0.42.0 < 0.42.6" | - |
Affected
| ||||||
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 0.43.0 < 0.43.7 Search vendor "Metabase" for product "Metabase" and version " >= 0.43.0 < 0.43.7" | - |
Affected
| ||||||
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 0.44.0 < 0.44.5 Search vendor "Metabase" for product "Metabase" and version " >= 0.44.0 < 0.44.5" | - |
Affected
| ||||||
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 1.41.0 < 1.41.9 Search vendor "Metabase" for product "Metabase" and version " >= 1.41.0 < 1.41.9" | - |
Affected
| ||||||
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 1.42.0 < 1.42.6 Search vendor "Metabase" for product "Metabase" and version " >= 1.42.0 < 1.42.6" | - |
Affected
| ||||||
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 1.43.0 < 1.43.7 Search vendor "Metabase" for product "Metabase" and version " >= 1.43.0 < 1.43.7" | - |
Affected
| ||||||
Metabase Search vendor "Metabase" | Metabase Search vendor "Metabase" for product "Metabase" | >= 1.44.0 < 1.44.5 Search vendor "Metabase" for product "Metabase" and version " >= 1.44.0 < 1.44.5" | - |
Affected
|