CVE-2024-55951

MEDIUM

Metabase <1.52.2.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed users. This is fixed in 1.52.2.5. Users on 1.52.0 or 1.52.1 or 1.5.2 should upgrade to 1.52.2.5. There are no workarounds for this issue aside from upgrading.

References (3)

Core 3
Core References
Various Sources x_refsource_misc
https://hub.docker.com/r/metabase/metabase/tags

Scores

CVSS v4 4.8
EPSS 0.0041
EPSS Percentile 32.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
metabase/metabase >= 1.52.0, < 1.52.2.5
Published Dec 16, 2024
Tracked Since Feb 18, 2026