Vulnerabilidades en metabase

29 resultados
Análisis Vexday

Metabase apresenta 24 CVEs catalogadas com 5 em nível crítico, mas apenas 1 sob exploração ativa conhecida, indicando risco moderado. A fraqueza dominante é exposição de informações (CWE-200), e a descoberta de 4 vulnerabilidades nos últimos 90 dias sugere superfície de ataque ainda em evolução, demandando monitoramento contínuo de patches.

CVE-2021-41277CRITICALGeoJSON URL validation can expose server files and environment variables to unauthorized usersEPSS 97.2%KEVCVE-2026-72898CRITICALMetabase SQL injection via password reset endpointEPSS 19.0%KEVCVE-2026-59827CRITICALMetabase: Unsafe Deserialization of H2 Query ResultsEPSS 3.8%CVE-2022-24853MEDIUMFile system exposure in MetabaseEPSS 2.5%CVE-2023-37470CRITICALMetabase vulnerable to remote code execution via POST /api/setup/validate API endpoint EPSS 1.3%CVE-2022-39361HIGHMetabase vulnerable to Remote Code Execution via H2EPSS 1.1%CVE-2022-24854HIGHDatabase bypassing any permissions in Metabase via SQlite attachEPSS 1.1%CVE-2026-59826CRITICALMetabase: Arbitrary Code Execution via Database Connection Detail BypassEPSS 1.0%CVE-2022-39362HIGHMetabase vulnerable to arbitrary SQL execution from queryhashEPSS 0.9%CVE-2026-72899CRITICALMetabase SQL injection via public card or dashboardEPSS 0.8%CVE-2026-33725HIGHMetabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization ImportEPSS 0.8%CVE-2026-50148CRITICALMetabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File WriteEPSS 0.8%CVE-2022-24855HIGHXSS vulnerability in MetabaseEPSS 0.7%CVE-2022-39359MEDIUMMetabase's GeoJSON validation doesn't prevent redirects to blocked URLsEPSS 0.6%CVE-2023-32680MEDIUMMissing SQL permissions check in metabaseEPSS 0.6%CVE-2022-39360MEDIUMMetabase SSO users able to circumvent IdP login by doing password resetEPSS 0.5%CVE-2026-92813MEDIUMMetabase through 0.63.18 SSRF via GeoJSON URL validation bypassEPSS 0.5%CVE-2022-39358MEDIUMMetabase vulnerable to circumvention of Locked parameter in Signed EmbeddingEPSS 0.5%CVE-2026-27464HIGHMetabase: Server-Side Template Injection via Notifications Endpoint Leads to RCEEPSS 0.5%CVE-2023-23628MEDIUMMetabase subject to Exposure of Sensitive Information to an Unauthorized Actor EPSS 0.4%