metabase is vulnerable to SQL Injection
100
Critical Risk
An unauthenticated SQL injection in the /api/session/reset_password endpoint lets a remote attacker run arbitrary SQL against the Metabase application database. That can create or take over an administrator account, change instance configuration, steal stored credentials for connected databases, and read or export data those connections can reach. This issue is being exploited in the wild. The fix closes the injection in the password-reset path; after upgrading, revoke sessions, review admin accounts and API keys, and rotate credentials for connected databases if the endpoint was reachable.
You are affected if you are using a version that falls within the vulnerable range and self-host Metabase with the /api/session/reset_password endpoint reachable by attackers.
metabase is vulnerable to SQL Injection in versions 0.58.0 - 0.58.22, 0.59.0 - 0.59.19, 0.60.0 - 0.60.15, 0.61.0 - 0.61.9, 0.62.0 - 0.62.7 and 0.63.0 - 0.63.2.
Upgrade the metabase:metabase library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant