CVE-2021-41277

CRITICAL KEV NUCLEI

Metabase - Local File Inclusion

Title source: llm

Description

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

Exploits (10)

nomisec WORKING POC 11 stars
by tahtaciburak · poc
https://github.com/tahtaciburak/CVE-2021-41277
nomisec WORKING POC 9 stars
by zer0yu · poc
https://github.com/zer0yu/CVE-2021-41277
nomisec SCANNER 5 stars
by z3n70 · poc
https://github.com/z3n70/CVE-2021-41277
nomisec WRITEUP 4 stars
by Vulnmachines · poc
https://github.com/Vulnmachines/Metabase_CVE-2021-41277
nomisec SCANNER 1 stars
by RubXkuB · infoleak
https://github.com/RubXkuB/PoC-Metabase-CVE-2021-41277
nomisec SCANNER
by kaizensecurity · poc
https://github.com/kaizensecurity/CVE-2021-41277
nomisec WORKING POC
by TheLastVvV · poc
https://github.com/TheLastVvV/CVE-2021-41277
nomisec SCANNER
by kap1ush0n · infoleak
https://github.com/kap1ush0n/CVE-2021-41277
nomisec WORKING POC
by Henry4E36 · poc
https://github.com/Henry4E36/Metabase-cve-2021-41277
vulncheck_xdb WORKING POC
infoleak
https://github.com/chengling-ing/CVE-2021-41277

Nuclei Templates (1)

Metabase - Local File Inclusion
HIGHby 0x_Akoko,DhiyaneshDK
Shodan: http.title:"Metabase" || http.title:"metabase"
FOFA: app="Metabase" || title="metabase" || app="metabase"

Scores

CVSS v3 10.0
EPSS 0.9435
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Details

CISA KEV 2024-11-12
VulnCheck KEV 2022-05-31
InTheWild.io 2022-05-31
ENISA EUVD EUVD-2021-28310
CWE
CWE-22 CWE-200
Status published
Products (10)
metabase/metabase 0.40.0
metabase/metabase 0.40.1
metabase/metabase 0.40.2
metabase/metabase 0.40.3
metabase/metabase 0.40.4
metabase/metabase 1.40.0
metabase/metabase 1.40.1
metabase/metabase 1.40.2
metabase/metabase 1.40.3
metabase/metabase 1.40.4
Published Nov 17, 2021
KEV Added Nov 12, 2024
Tracked Since Feb 18, 2026