Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhcq-xc7j-xfj8

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 4.9

Описание

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.9
nvd
1 день назад

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-918