PT-2026-2314 · Metabase · Metabase
Lowimrk
·
Publicado
2026-01-12
·
Atualizado
2026-04-10
·
CVE-2026-22805
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Metabase versions prior to 55.13
Metabase versions prior to 56.3
Metabase versions prior to 57.1
Description
Metabase is an open-source data analytics platform. Self-hosted instances allowing user-created subscriptions may be potentially impacted if colocated with other unsecured resources.
Recommendations
Update to Metabase version 55.13 or later.
Update to Metabase version 56.3 or later.
Update to Metabase version 57.1 or later.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Metabase