Описание
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable MB_CUSTOM_GEOJSON_ENABLED was also added to disable custom GeoJSON completely (true by default).
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.41.0 (включая) до 0.41.9 (исключая)Версия от 0.42.0 (включая) до 0.42.6 (исключая)Версия от 0.43.0 (включая) до 0.43.7 (исключая)Версия от 0.44.0 (включая) до 0.44.5 (исключая)Версия от 1.41.0 (включая) до 1.41.9 (исключая)Версия от 1.42.0 (включая) до 1.42.6 (исключая)Версия от 1.43.0 (включая) до 1.43.7 (исключая)Версия от 1.44.0 (включая) до 1.44.5 (исключая)
Одно из
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00206
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200
CWE-601
EPSS
Процентиль: 43%
0.00206
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200
CWE-601