Metabase security update-CVE-2021-41277
NAME
Metabase – Metabase
- Platforms Affected:
Metabase - Risk Level:
low - CVE Type:
Improper input validation
DESCRIPTION
CVE-2021-41277 is an improper input validation vulnerability impacting Metabase versions 0.40.0, 0.40.1, 0.40.2, 0.40.3 and 0.40.4. A proof of concept (PoC) was observed in open source and subsequently shared in the underground.
CVSS Information:
- CVSS 2.0 SCORE: 5
- CVSS 3.0 SCORE: 10
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
- PoC Link:
hXXps://github[.]com/projectdiscovery/nuclei-templates/commit/94e1c1315879d35a0fba7293f3cf19c5a4194016
MITIGATION
Metabase addressed the vulnerability in a GitHub software development platform with a patch.
- Reference Link:
https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0 - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.