Skip to main content

Share story

Security

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Image: Primary
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability, which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance. Metabase said in an advisory that it recently identified that Metabase Cloud was attacked by someone utilizing an unknown zero-day security vulnerability in versions 1.58 and above. Metabase Cloud instances have already been updated to the latest version. Users running self-hosted versions are advised to apply security patches released by Metabase with immediate effect.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from thehackernews.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

Snorkel AI raises $350 million at $3.5 billion valuation

Snorkel AI raised $350 million in fresh funding at a $3.5 billion valuation, CEO Alex Ratner told Reuters. The company sells a data-development platform that combines people and AI agents to create and vet data used in AI systems....

Capital AI
Capital AI

Spott raises €18.3 million to expand recruitment software

Leuven-based Spott has raised €18.3 million ($21 million) in a Series A led by Balderton Capital, with Base10 Partners, Y Combinator and Fortino participating. The recruitment-software company plans to use the funding for expansio...

Security Infrastructure
Security Infrastructure

Public research shows SharePoint flaw permits authenticated code execution

A SharePoint Server vulnerability Microsoft initially rated as a moderate spoofing issue can let an authenticated attacker execute code, according to technical details and working exploit markup published by Viettel Cyber Security...

Capital Infrastructure
Capital Infrastructure

Morphotonics raises €40 million for optics manufacturing and data-center push

Dutch manufacturing startup Morphotonics has raised €40 million in an extended round backed by investors including 3M Ventures, Innovation Industries, Invest-NL and the European Investment Bank. The company makes machines that sta...