Home / Companies / Metabase / Blog / Post Details
Content Deep Dive

Security update available for Metabase - Please upgrade now

Blog post from Metabase

Post Details
Company
Date Published
Author
Sameer Al-Sakran
Word Count
503
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

Metabase disclosed a security incident involving a previously unknown vulnerability affecting self-hosted versions 0.58 and later, while Metabase Cloud instances have already been patched. The flaw could allow an attacker to exploit the password-reset endpoint to inject SQL into the Metabase application database, potentially gaining administrator access, altering configuration, obtaining database credentials, accessing connected data, and exporting it. Users are advised to immediately upgrade to the latest safe point release for their version, revoke active sessions, review API keys and administrator accounts, rotate connected-database credentials, and inspect warehouse logs and Metabase activity for unauthorized behavior. A likely compromise is indicated by a failed POST request to `/api/session/reset_password` followed by a successful GET request to `/api/user/current`; organizations unable to update immediately should temporarily block the password-reset endpoint.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.