CVE-2022-24855
In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links that could lead to account takeover.
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links that could lead to account takeover. Users are advised to either upgrade immediately, or block access in your firewall to `/_internal` endpoints for Metabase. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.71% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- metabase/metabase
- Source
- security-advisories@github.com
References
- https://github.com/metabase/metabase/releases/tag/v0.42.4Release Notes, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-wjw6-wm9w-7ggrRelease Notes, Third Party Advisory
- https://github.com/metabase/metabase/releases/tag/v0.42.4Release Notes, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-wjw6-wm9w-7ggrRelease Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.