CVE-2022-39359
Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network.
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable `MB_CUSTOM_GEOJSON_ENABLED` was also added to disable custom GeoJSON completely (`true` by default).
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-601
- Affected
- metabase/metabase
- Source
- security-advisories@github.com
References
- https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771ePatch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4Third Party Advisory
- https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771ePatch, Third Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.