Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
A zero-day SQL-injection vulnerability in Metabase Cloud is actively being exploited, potentially impacting a wide range of organizations beyond Metabase customers. The vulnerability allows remote attackers to gain administrator access to Metabase instances, steal credentials, and access sensitive data. While Metabase Cloud users have been automatically upgraded, self-hosted instances with exposed /api/session/reset_password endpoints remain vulnerable, leading to data breaches and potential follow-on attacks against clients and downstream customers. Metabase urges self-hosted users to patch immediately and recommends incident response measures for exposed endpoints.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
.jpg?width=720&quality=80&disable=upscale)