CISOOnline

Metabase SQLi exploit grants attackers total access

Metabase said that after it discovered the attack, it immediately blocked the exploited endpoints, patched the vulnerability, terminated relevant sessions, and revoked credentials used in the incident. Metabase Cloud customers have already been upgraded and patched against the vulnerability, but self-hosted Metabase customers may still be vulnerable unless they have patched.

“This vulnerability allows attackers to have unmitigated, raw SQL access to the Metabase database,” said Scott Miserendino, CTO at DataBee. They can steal or alter account credentials for connected databases, create new administrator accounts, change app configurations, escalate privileges, or even “degrade, alter or destroy” information.

He emphasized that this vulnerability can also affect platforms that use original equipment manufacturer (OEM) versions of  Metabase as part of their infrastructure. This means affected users may not even know they are affected, because they are not aware that Metabase is part of the product they purchased.



Source link