CVE-2022-39361

HIGH

Metabase < 0.41.9 - Remote Code Execution

Title source: rule
STIX 2.1

Description

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Execution (RCE), which can be abused by users able to write SQL queries on H2 databases. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer allows DDL statements in H2 native queries.

Scores

CVSS v3 8.8
EPSS 0.0161
EPSS Percentile 81.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-441 CWE-20
Status published
Products (1)
metabase/metabase 0.41.0 - 0.41.9
Published Oct 26, 2022
Tracked Since Feb 18, 2026