Metabase Zero-Day Exploited in the Wild: Unauthenticated SQL Injection Leading to Full Admin Access
ID: 3ca5b128-f6be-5e60-a535-14b794cf25cc
STIX ID: report--3ca5b128-f6be-5e60-a535-14b794cf25cc
Feed Name: Resecurity
Metabase disclosed a critical, actively exploited unauthenticated SQL injection zero-day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) in the /api/session/reset_password endpoint that affects self-hosted versions v1.58–v1.63; the flaw stems from HoneySQL {:raw "SQL"} injection and lack of type validation, allowing an attacker to reset administrator passwords, obtain admin privileges, recover stored credentials for connected databases, and exfiltrate data. Metabase Cloud was patched before disclosure, while self-hosted users must upgrade to the specified patched releases (58.24, 59.21, 60.17, 61.11, 62.9, 63.5) or block the endpoint, assume possible compromise, rotate credentials, and follow the vendor’s post-compromise checklist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
