Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-32680

Опубликовано: 18 мая 2023
Источник: nvd
CVSS3: 5.8
CVSS3: 9.6
EPSS Низкий

Описание

Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Metabase didn't enforce that requirement. This lack of enforcement meant that: Anyone–including people in sandboxed groups–could edit SQL snippets. They could edit snippets via the API or, in the application UI, when editing the metadata for a model based on a SQL question, and people in sandboxed groups could edit a SQL snippet used in a query that creates their sandbox. If the snippet contained logic that restricted which data that person could see, they could potentially edit that snippet and change their level of data access. The permissions model for SQL snippets has been fixed in Metabase versions 0.46.3, 0.45.4, 0.44.7, 1.46.3, 1.45.4, and 1.44.7. Users are advised to upgrade. Users unable to upgrade should ensure that SQL queries used to create sandboxes exc

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Версия до 0.44.7 (исключая)
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Версия от 0.45.0 (включая) до 0.45.4 (исключая)
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Версия от 0.46.0 (включая) до 0.46.3 (исключая)
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 1.44.7 (исключая)
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Версия от 1.45.0 (включая) до 1.45.4 (исключая)
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Версия от 1.46.0 (включая) до 1.46.3 (исключая)

EPSS

Процентиль: 34%
0.0014
Низкий

5.8 Medium

CVSS3

9.6 Critical

CVSS3

Дефекты

CWE-306

EPSS

Процентиль: 34%
0.0014
Низкий

5.8 Medium

CVSS3

9.6 Critical

CVSS3

Дефекты

CWE-306