Metabase Discloses Critical SQL Injection Zero-Day (CVSS 10) Under Active Exploitation

Metabase has revealed a critical SQL injection zero-day vulnerability, rated CVSS 10, that is actively being exploited in the wild. The flaw allows an unauthenticated remote attacker to gain full administrator access to an instance. Self-hosted instances on version 1.58 and above are at risk, and immediate patching is recommended.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai