Security update available for Metabase - Please upgrade now
Blog post from Metabase
Metabase disclosed a security incident involving a previously unknown vulnerability affecting self-hosted versions 0.58 and later, while Metabase Cloud instances have already been patched. The flaw could allow an attacker to exploit the password-reset endpoint to inject SQL into the Metabase application database, potentially gaining administrator access, altering configuration, obtaining database credentials, accessing connected data, and exporting it. Users are advised to immediately upgrade to the latest safe point release for their version, revoke active sessions, review API keys and administrator accounts, rotate connected-database credentials, and inspect warehouse logs and Metabase activity for unauthorized behavior. A likely compromise is indicated by a failed POST request to `/api/session/reset_password` followed by a successful GET request to `/api/user/current`; organizations unable to update immediately should temporarily block the password-reset endpoint.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.