Vulnerability Description
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Execution (RCE), which can be abused by users able to write SQL queries on H2 databases. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer allows DDL statements in H2 native queries.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Metabase | Metabase | >= 0.41.0, < 0.41.9 |
Related Weaknesses (CWE)
References
- https://github.com/metabase/metabase/security/advisories/GHSA-gqpj-wcr3-p88vThird Party Advisory
- https://github.com/metabase/metabase/security/advisories/GHSA-gqpj-wcr3-p88vThird Party Advisory
FAQ
What is CVE-2022-39361?
CVE-2022-39361 is a vulnerability with a CVSS score of 8.8 (HIGH). Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Execution (RCE), which can b...
How severe is CVE-2022-39361?
CVE-2022-39361 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39361?
Check the references section above for vendor advisories and patch information. Affected products include: Metabase Metabase.