Security Advisory

CVE-2022-39358

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-10-26 00:00:00
Last updated 2025-04-23 16:42:54
Assigner GitHub_M
CVSS score 6.5
State PUBLISHED

Description

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious request to the backend. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6.