Skip to main content
Back to Newswire
Security

Metabase SQLi zero-day exploited in customer data-theft attacks

Metabase SQLi zero-day exploited in customer data-theft attacks Image: Primary
Metabase disclosed on Thursday that a critical SQL injection vulnerability was exploited in zero-day attacks to breach customer instances and steal data, impacting companies including Framework and Tally, the company said. Metabase CEO Sameer Al-Sakran warned in a blog post that Metabase Cloud was attacked by someone utilizing an unknown security vulnerability in versions 1.58 and above. The company confirmed it blocked the endpoints used for the attack and immediately rolled out a fix for the vulnerability, which is rated Critical with a CVSS score of 10.0. The vulnerability is an unauthenticated SQL injection flaw that can give a remote attacker administrator access to a customer's instance, according to a security advisory. From there, the attacker could change application configuration, steal stored credentials for connected databases, read any data accessible through those connections, and export data. Metabase said its Cloud customers have already been upgraded and patched, while organizations running vulnerable self-hosted installations must update manually. Laptop maker Framework confirmed customer information was stolen after attackers compromised its Metabase instance, according to a breach notification shared with BleepingComputer. The stolen data includes full names, email addresses, login IP addresses, billing and shipping address information, phone number, and company name. Framework said Metabase notified the company on August 6 that its instance had been vulnerable and accessed by the attacker on August 3. Tally notified users that its Metabase analytics environment was compromised on August 3, exposing email addresses and password hashes. LexisNexis warned customers it was impacted by a cyberattack at a third-party vendor and said its Metabase API was impacted, though it is unclear whether customer data was exposed.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer and reviewed by the T&B editorial agent team.