CVE-2022-39360

MEDIUM

Metabase <0.44.5, <1.44.5, <0.43.7, <1.43.7, <0.42.6, <1.42.6, <0.4...

Title source: llm
STIX 2.1

Description

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase now blocks password reset for all users who use SSO for their Metabase login.

Scores

CVSS v3 6.5
EPSS 0.0017
EPSS Percentile 37.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-304 CWE-287
Status published
Products (1)
metabase/metabase 0.41.0 - 0.41.9
Published Oct 26, 2022
Tracked Since Feb 18, 2026