CVE-2022-24855

Source
https://cve.org/CVERecord?id=CVE-2022-24855
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24855.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-24855
Aliases
  • GHSA-wjw6-wm9w-7ggr
Published
2022-04-14T21:35:11Z
Modified
2025-12-04T10:20:06.744003Z
Severity
  • 8.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
XSS vulnerability in Metabase
Details

Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint /_internal that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links that could lead to account takeover. Users are advised to either upgrade immediately, or block access in your firewall to /_internal endpoints for Metabase. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24855.json"
}
References

Affected packages

Git / github.com/metabase/metabase

Affected ranges

Type
GIT
Repo
https://github.com/metabase/metabase
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.40.0"
        },
        {
            "fixed": "1.40.8"
        },
        {
            "introduced": "0.40.0"
        },
        {
            "fixed": "0.40.8"
        }
    ]
}
Type
GIT
Repo
https://github.com/metabase/metabase
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.41.0"
        },
        {
            "fixed": "1.41.7"
        },
        {
            "introduced": "0.41.0"
        },
        {
            "fixed": "0.41.7"
        }
    ]
}
Type
GIT
Repo
https://github.com/metabase/metabase
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.42.0"
        },
        {
            "fixed": "1.42.4"
        },
        {
            "introduced": "0.42.0"
        },
        {
            "fixed": "0.42.4"
        }
    ]
}

Affected versions

v0.*
v0.40.0
v0.40.1
v0.40.2
v0.40.3
v0.40.3.1
v0.40.4
v0.40.5
v0.40.6
v0.40.7
v0.41.0
v0.41.1
v0.41.2
v0.41.3
v0.41.3.1
v0.41.5
v0.41.6
v0.42.0
v0.42.1
v0.42.2
v0.42.3
v1.*
v1.40.0
v1.40.1
v1.40.2
v1.40.3
v1.40.3.1
v1.40.4
v1.40.5
v1.40.6
v1.40.7
v1.41.0
v1.41.1
v1.41.2
v1.41.3
v1.41.3.1
v1.41.5
v1.41.6
v1.42.0
v1.42.1
v1.42.2
v1.42.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24855.json"