PT-2025-13544 · Metabase · Metabase

Published

2025-03-28

·

Updated

2025-03-28

·

CVE-2025-30371

CVSS v4.0

2.1

Low

VectorAV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Metabase versions prior to 0.52.16.4 Metabase versions prior to 0.53.8 Metabase versions prior to 1.52.16.4 Metabase versions prior to 1.53.8
Description Metabase is a business intelligence and embedded analytics tool. The issue concerns the circumvention of local link access protection in the GeoJson endpoint. Self-hosted Metabase instances using the GeoJson feature could be impacted if their Metabase is colocated with other unsecured resources.
Recommendations For versions prior to 0.52.16.4, update to version 0.52.16.4 or later. For versions prior to 0.53.8, update to version 0.53.8 or later. For versions prior to 1.52.16.4, update to version 1.52.16.4 or later. For versions prior to 1.53.8, update to version 1.53.8 or later. As a temporary workaround, consider migrating to Metabase Cloud or redeploying Metabase in a dedicated subnet with strict outbound port controls.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30371
GHSA-8XF9-9JC8-QP98

Affected Products

Metabase