Metabase Patches Vulnerability Exploited as Zero-Day
Summary
Metabase has released a patch for a critical security vulnerability that was being exploited as a zero-day. This defect allowed unauthenticated, remote attackers to gain administrative access to Metabase instances.
IFF Assessment
This vulnerability allows unauthenticated remote attackers to gain administrative access, which is a severe threat to organizations using Metabase.
Severity
The vulnerability allows for unauthenticated remote code execution leading to administrative access, indicating a high severity. This was also exploited as a zero-day, further increasing its risk.
Defender Context
This zero-day vulnerability in Metabase highlights the importance of prompt patching for self-hosted analytics platforms. Defenders should prioritize updating Metabase instances and actively monitor for any signs of compromise, as administrative access can lead to further system exploitation.