CVE-2021-41277
CRITICAL KEV NUCLEIMetabase - Local File Inclusion
Title source: llmDescription
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
Exploits (10)
nomisec
WRITEUP
4 stars
by Vulnmachines · poc
https://github.com/Vulnmachines/Metabase_CVE-2021-41277
nomisec
SCANNER
1 stars
by RubXkuB · infoleak
https://github.com/RubXkuB/PoC-Metabase-CVE-2021-41277
Nuclei Templates (1)
Metabase - Local File Inclusion
HIGHby 0x_Akoko,DhiyaneshDK
Shodan:
http.title:"Metabase" || http.title:"metabase"
FOFA:
app="Metabase" || title="metabase" || app="metabase"
References (3)
Scores
CVSS v3
10.0
EPSS
0.9435
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Details
CISA KEV
2024-11-12
VulnCheck KEV
2022-05-31
InTheWild.io
2022-05-31
ENISA EUVD
EUVD-2021-28310
CWE
CWE-22
CWE-200
Status
published
Products (10)
metabase/metabase
0.40.0
metabase/metabase
0.40.1
metabase/metabase
0.40.2
metabase/metabase
0.40.3
metabase/metabase
0.40.4
metabase/metabase
1.40.0
metabase/metabase
1.40.1
metabase/metabase
1.40.2
metabase/metabase
1.40.3
metabase/metabase
1.40.4
Published
Nov 17, 2021
KEV Added
Nov 12, 2024
Tracked Since
Feb 18, 2026