Home / Companies / Metabase / Blog / Post Details
Content Deep Dive

Vulnerability post-mortem: July 2023

Blog post from Metabase

Post Details
Company
Date Published
Author
The Metabase Team
Word Count
3,062
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

Metabase recently faced a critical security vulnerability involving a set of issues with the H2 database integration, leading to an unauthenticated Remote Code Execution (RCE) that severely impacted the community. The vulnerability, which allowed attackers to run arbitrary code on Metabase servers, stemmed from multiple factors including the use of unicode to bypass keyword checks, misinterpretation of connection strings, and SQL injection through the TRACE_LEVEL_SYSTEM_OUT option, combined with an exposed setup token. Upon discovery, Metabase implemented a phased response plan, issuing patches to cloud customers and eventually releasing updates to the open-source community while trying to prevent the exploit from spreading before users could upgrade. Despite these efforts, some security researchers independently publicized the vulnerability, leading to a broader awareness and urgency to update. The incident prompted Metabase to enhance scrutiny on client-supplied connection strings, improve incident response processes, and remove H2 as a supported analytics database.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.