GeoJSON URL validation can expose server files and environment variables to unauthorized users
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 10epss 97%
de la publicación al arma4 días
Publicada en NVD17 nov
1ª PoC+4d
CISA KEV+1091d
probabilidad de explotación
97%top 1% de las CVE
explotación observada
síCISA + VulnCheck
12 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2024-12-03
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Productos afectados
metabase · metabasePoCs públicas encontradas — 12
githubgithub.com/tahtaciburak/CVE-2021-41277★ 11githubgithub.com/zer0yu/CVE-2021-41277★ 9githubgithub.com/z3n70/CVE-2021-41277★ 5githubgithub.com/Vulnmachines/Metabase_CVE-2021-41277★ 4githubgithub.com/RubXkuB/PoC-Metabase-CVE-2021-41277★ 1githubgithub.com/TheLastVvV/CVE-2021-41277★ 0githubgithub.com/Henry4E36/Metabase-cve-2021-41277★ 0githubgithub.com/kap1ush0n/CVE-2021-41277★ 0githubgithub.com/kaizensecurity/CVE-2021-41277★ 0vulncheckvulncheck.com/xdb/ade2199af4d8no verificadovulncheckvulncheck.com/xdb/d82529f295a2no verificadovulncheckvulncheck.com/xdb/4a3d504338feno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.