Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Additional critical Metabase security vulnerabilities announced today (metabase.com)
3 points by nfm on July 29, 2023 | hide | past | favorite | 2 comments


Metabase announced a patch release for a critical vulnerability a little over a week ago: https://www.metabase.com/blog/security-advisory

Today they have announced further, related vulnerabilities, and if you're running your own instance you should patch again, or disable your instance until you have a chance to do so.

The vulnerabilities allow an unauthenticated attacker to run arbitrary commands with the same privileges as the Metabase server on the server you are running Metabase on. This would allow arbitrary querying of any database that Metabase is connected to.


Very important! Another update




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: