CVE-2022-39358

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-39358
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39358.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-39358
Related
  • GHSA-8qgm-9mj6-36h3
Published
2022-10-26T19:15:10Z
Modified
2025-02-19T03:30:38.080229Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious request to the backend. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6.

References

Affected packages

Git / github.com/metabase/metabase

Affected ranges

Type
GIT
Repo
https://github.com/metabase/metabase
Events

Affected versions

v0.*

v0.42.0
v0.42.1
v0.42.2
v0.42.3
v0.42.4
v0.42.4.1
v0.42.5

v1.*

v1.42.0
v1.42.1
v1.42.2
v1.42.3
v1.42.4
v1.42.4.1
v1.42.5