PT-2025-7794 · Metabase · Metabase Enterprise Edition

Perivamsipublished

·

Published

2025-02-24

·

Updated

2025-02-28

·

CVE-2025-27141

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Metabase Enterprise Edition versions 1.47.0 through 1.49.x Metabase Enterprise Edition versions 1.50.0 through 1.50.35 Metabase Enterprise Edition versions 1.51.0 through 1.51.13 Metabase Enterprise Edition versions 1.52.0 through 1.52.10
Description The issue allows users with impersonation permissions to see results of cached questions, even if their permissions don’t allow them to see the data. This occurs when an impersonated user runs a question that was previously run by another user, resulting in the impersonated user seeing the same results as the previous user. These cached results may include data the impersonated user should not have access to.
Recommendations For Metabase Enterprise Edition versions 1.47.0 through 1.49.x, upgrade to a major version with an available fix. For Metabase Enterprise Edition versions 1.50.0 through 1.50.35, upgrade to version 1.50.36 or later. For Metabase Enterprise Edition versions 1.51.0 through 1.51.13, upgrade to version 1.51.14 or later. For Metabase Enterprise Edition versions 1.52.0 through 1.52.10, upgrade to version 1.52.11 or later. As a temporary workaround, consider disabling question caching to mitigate the risk of exploitation.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-27141
GHSA-6CC4-H534-XH5P

Affected Products

Metabase Enterprise Edition