Metabase Zero-Day Exploited in the Wild Allows Unauthenticated Administrator Access
Metabase has warned that a maximum-severity security vulnerability affecting its business intelligence and data visualization software has been exploited in the wild as a zero-day vulnerability.
The vulnerability, which has not yet been assigned a CVE identifier and carries a CVSS score of 10.0, allows an unauthenticated remote attacker to inject arbitrary SQL code into the Metabase application database, potentially gaining administrator-level access to the instance.
With the privileged access obtained through exploitation, an attacker could modify application configurations, steal stored credentials for connected databases, access and read data available through those connections, and export sensitive information.
Metabase stated that it recently discovered an attack against Metabase Cloud involving an unknown ("zero-day") vulnerability affecting versions 1.58 and later.

Metabase Cloud instances have already been upgraded to the latest version. Organizations using self-hosted deployments are strongly advised to immediately apply the security patches released by Metabase.
The following versions are affected:
= x.58.0, < x.58.23 — fixed in x.58.24
= x.59.0, < x.59.20 — fixed in x.59.21
= x.60.0, < x.60.16 — fixed in x.60.17
= x.61.0, < x.61.10 — fixed in x.61.11
= x.62.0, < x.62.8 — fixed in x.62.9
= x.63.0, < x.63.3 — fixed in x.63.5
As a temporary mitigation until the patches can be applied, organizations are advised to block access to the following endpoint:
/api/session/reset_password
After completing the upgrade, customers whose /api/session/reset_password endpoint was publicly accessible are advised to take the following actions:
Invalidate all active user sessions by accessing the Metabase Application Database and deleting all rows from the core_session table.
Review API keys and remove any unrecognized or unauthorized keys.
Check administrator accounts for unexpected changes.
Rotate credentials for all connected databases.
Review data warehouse logs for signs of unauthorized access.
Examine Metabase activity and query history for unexpected or unauthorized activity.
Metabase did not disclose specific details regarding the malicious activity but shared the following Indicators of Compromise (IoCs):
A POST /api/session/reset_password request resulting in an HTTP 400 status code.
Followed by a GET /api/user/current request resulting in an HTTP 200 status code.
Metabase CEO Sameer Al-Sakran stated that if this pattern is found in application logs or Metabase server access logs, there is a high likelihood that the affected instance has been compromised.
One of the companies affected by the incident is Framework. According to Engadget, the computer manufacturer notified its customers that customer names, login IP addresses, physical addresses, phone numbers, and email addresses were accessed during the cyberattack. The company stated that order and payment information was not accessed.
Exactly three years earlier, Metabase addressed another highly critical security vulnerability, CVE-2023-38646 (CVSS score: 9.8), which could allow unauthenticated remote code execution on affected installations.
Some of the measures that can be taken to protect against these types of attacks include;
Immediately updating Metabase and applying the latest security patches.
Blocking the /api/session/reset_password endpoint until the update is completed.
nvalidating active sessions and reviewing API keys.
Rotating credentials for connected databases.
Reviewing Metabase and database logs for IoCs and unauthorized access.
Restricting Metabase access using WAF, firewall, and access control policies.
For more information or professional assistance, please contact our security experts at. info@zerosecond.ae.





















Comments