Urgent: Upgrade your Metabase installation now. H2-related remote code execution found
Blog post from Metabase
Metabase has addressed several vulnerabilities related to the H2 in-memory database, which allowed executable code injection via connection strings, by disabling support for H2 altogether. This decision follows multiple discoveries of vulnerabilities within a week by security researchers, leading to Metabase's removal of H2 to prevent future issues. Users are urged to upgrade their Metabase installations immediately to safeguard against these risks, particularly those running versions 43, 44, or 45. The vulnerabilities are not applicable to older versions below 0.43 or to users utilizing H2 as an application database within Metabase. Metabase Cloud customers have had vulnerable endpoints blocked and patches applied, while self-hosted users are provided with updated release versions. The company extends gratitude to several security researchers and teams for their roles in identifying and reporting these vulnerabilities.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.