Metabase SQLi zero-day exploited in customer data-theft attacks

Summary

A critical zero-day SQL injection vulnerability in Metabase has been exploited in attacks, leading to the theft of customer data. The attacks are known to have impacted instances running Framework and Tally.

IFF Assessment

FOE

This vulnerability allows attackers to steal sensitive customer data, representing a significant win for attackers and a setback for defenders.

Severity

9.8 Critical (AI Estimated)

The CVSS score is estimated high due to the critical nature of SQL injection, the zero-day aspect indicating no immediate patches, and the direct impact of data theft, likely with high impact on confidentiality, integrity, and availability.

Defender Context

Defenders should prioritize patching Metabase instances immediately if available, and monitor for signs of unauthorized access or data exfiltration. This highlights the ongoing risk of zero-day vulnerabilities in widely used data analytics tools.

Read Full Story →