PT-2022-27030 · Metabase · Metabase

Ronan Donohue

·

Published

2022-10-26

·

Updated

2022-10-28

·

CVE-2022-43776

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Metabase versions prior to 44.5
Description The issue concerns the url parameter of the "/api/geojson" endpoint, which can be exploited to perform Server Side Request Forgery attacks. It is noted that previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.
Recommendations For versions prior to 44.5, update to version 44.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/api/geojson" endpoint until the update is applied. Avoid using the url parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-43776

Affected Products

Metabase