Critical SQL Injection Zero-Day (CVSS 10) in Metabase Actively Exploited
Metabase, a popular open-source business intelligence tool, has disclosed a critical SQL injection zero-day vulnerability (CVSS 10) that allows unauthenticated remote attackers to gain full administrator access. Metabase confirms active exploitation in the wild, with self-hosted instances on version 1.58 and above being at risk. The vulnerability could expose entire data estates by allowing attackers to steal credentials, modify configurations, and read data.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai