Home / Companies / Metabase / Blog / Post Details
Content Deep Dive

Security update available for Metabase - Please upgrade now

Blog post from Metabase

Post Details
Company
Date Published
Author
Sameer Al-Sakran
Word Count
499
Company Posts That Month
1
Language
English
Hacker News Points
-
Post removed?
No
Summary

Metabase disclosed a security incident involving a previously unknown vulnerability affecting self-hosted versions 0.58 and later, which allowed attackers to exploit the public password-reset endpoint, inject arbitrary SQL into the application database, and potentially obtain administrator access. Such access could enable configuration changes, theft of stored database credentials, access to connected data, and data exports. Metabase Cloud instances have already been patched, while self-hosted users are urged to upgrade immediately to the latest safe point release for their major version, with versions earlier than 0.58 unaffected. Organizations whose password-reset endpoint was publicly accessible should revoke user sessions, inspect API keys and administrator accounts, rotate connected-database credentials, and review warehouse, activity, and query logs for suspicious activity. A likely compromise is indicated by a failed POST request to the password-reset endpoint followed by a successful GET request to the current-user endpoint, and users unable to upgrade promptly are advised to temporarily block the affected endpoint.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.