2 min read
‧ 2 min read
An independent security researcher Sho Odagiri from GMO Cybersecurity by Ierae submitted a severe issue with Metabase. We generally don’t blog about every bug, but this one is dangerous so we want to make sure that we reach out on all channels to our community to let them know that they should pay attention to this.
While we have no evidence that the vulnerability was ever exploited in the wild, and exploiting this vulnerability isn’t simple, if you are self-hosting Metabase, you should IMMEDIATELY update your Metabase instances (if you have not already).
The vulnerability allows an authenticated user (including embedding users) to retrieve sensitive information from a Metabase instance, including database access credentials. For more info, check out the security advisory.
No action needed. We’ve already upgraded your Metabase, and you’re no longer vulnerable.
IF you haven’t already, you should immediately upgrade to the latest point version of whichever Metabase version you’re running.
See the list of minimum safe releases below, and find the latest point version for the Metabase version you’re running. If you’re running a point version below that version, you’re still vulnerable and should upgrade immediately.
For example, if you are running 1.58.6, you should upgrade to 1.58.7 release or later. If you’re running a version of Metabase below version 55, you should upgrade to one of the versions listed below. You can find your current version by clicking on the “gear” icon in the upper right and selecting “About Metabase.”
Email us at help@metabase.com so we can provide you the appropriate patches.
The downloads below include the minimum safe release for each Metabase version.
v0.55.20
v1.55.20
v0.56.20
v1.56.20
v0.57.13
v1.57.13
v0.58.7
v1.58.7
We thank Sho Odagiri from GMO Cybersecurity by Ierae, Inc for discovering and disclosing this vulnerability.