Описание
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.44.5 (исключая)
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00265
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-918
CWE-918
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.
EPSS
Процентиль: 50%
0.00265
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-918
CWE-918