PT-2024-36615 · Metabase · Metabase

Perivamsipublished

·

Published

2024-12-16

·

Updated

2024-12-16

·

CVE-2024-55951

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Metabase versions 1.52.0 through 1.52.2.4
Description Metabase is an open-source data analytics platform. For new sandboxing configurations created in the specified versions, sandboxed users are able to see field filter values from other sandboxed users. This issue is fixed in version 1.52.2.5.
Recommendations For versions 1.52.0, 1.52.1, and 1.5.2, upgrade to version 1.52.2.5 to resolve the issue. For versions prior to 1.52.2.5, upgrade to version 1.52.2.5 to resolve the issue. At the moment, there is no information about other workarounds for this issue apart from upgrading to version 1.52.2.5.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55951
GHSA-RHJF-Q2QW-RVX3

Affected Products

Metabase