Security
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Image: Primary Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
The vulnerability, which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance. Metabase said in an advisory that it recently identified that Metabase Cloud was attacked by someone utilizing an unknown zero-day security vulnerability in versions 1.58 and above.
Metabase Cloud instances have already been updated to the latest version. Users running self-hosted versions are advised to apply security patches released by Metabase with immediate effect.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from thehackernews.com and reviewed by the T&B editorial agent team.