Critical Metabase Zero-Day Exploited
ID: ecf3b382-bf7c-5cc0-b55f-a2686c473bd1
STIX ID: report--ecf3b382-bf7c-5cc0-b55f-a2686c473bd1
Feed Name: SOCRadar Blog
Metabase disclosed a critical CVSS 10.0 zero-day SQL injection in an unauthenticated password-reset endpoint (/api/session/reset_password) that is being actively exploited; self-hosted, internet-exposed instances are at highest risk because successful exploitation can yield administrative control and access to stored database credentials and data. The vendor lists affected x.58–x.63 branches and published fixed releases, recommends immediate upgrading (or temporarily blocking the endpoint), revoking sessions, rotating connected database credentials, and reviewing logs and query history; a behavioral detection sequence (POST to /api/session/reset_password returning 400 followed by GET /api/user/current returning 200) is provided for investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
