Security update available for Metabase - Please upgrade now
Blog post from Metabase
Metabase disclosed a security incident involving a previously unknown vulnerability affecting self-hosted versions 0.58 and later, which allowed attackers to exploit the public password-reset endpoint, inject arbitrary SQL into the application database, and potentially obtain administrator access. Such access could enable configuration changes, theft of stored database credentials, access to connected data, and data exports. Metabase Cloud instances have already been patched, while self-hosted users are urged to upgrade immediately to the latest safe point release for their major version, with versions earlier than 0.58 unaffected. Organizations whose password-reset endpoint was publicly accessible should revoke user sessions, inspect API keys and administrator accounts, rotate connected-database credentials, and review warehouse, activity, and query logs for suspicious activity. A likely compromise is indicated by a failed POST request to the password-reset endpoint followed by a successful GET request to the current-user endpoint, and users unable to upgrade promptly are advised to temporarily block the affected endpoint.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.