CVE-2022-39359

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable `MB_CUSTOM_GEOJSON_ENABLED` was also added to disable custom GeoJSON completely (`true` by default).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
References () https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771e - Patch, Third Party Advisory () https://github.com/metabase/metabase/commit/057e2d67fcbeb6b48db68b697e022243e3a5771e - Patch, Third Party Advisory
References () https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4 - Third Party Advisory () https://github.com/metabase/metabase/security/advisories/GHSA-w5j7-4mgm-77f4 - Third Party Advisory

Information

Published : 2022-10-26 19:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-39359

Mitre link : CVE-2022-39359

CVE.ORG link : CVE-2022-39359


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')