Home / Companies / Metabase / Blog / Post Details
Content Deep Dive

Urgent: Upgrade your Metabase installation now. H2-related remote code execution found

Blog post from Metabase

Post Details
Company
Date Published
Author
The Metabase Team
Word Count
657
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

Metabase has addressed several vulnerabilities related to the H2 in-memory database, which allowed executable code injection via connection strings, by disabling support for H2 altogether. This decision follows multiple discoveries of vulnerabilities within a week by security researchers, leading to Metabase's removal of H2 to prevent future issues. Users are urged to upgrade their Metabase installations immediately to safeguard against these risks, particularly those running versions 43, 44, or 45. The vulnerabilities are not applicable to older versions below 0.43 or to users utilizing H2 as an application database within Metabase. Metabase Cloud customers have had vulnerable endpoints blocked and patches applied, while self-hosted users are provided with updated release versions. The company extends gratitude to several security researchers and teams for their roles in identifying and reporting these vulnerabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.