Lucene search

K
cve[email protected]CVE-2023-38646
HistoryJul 21, 2023 - 3:15 p.m.

CVE-2023-38646

2023-07-2115:15:10
web.nvd.nist.gov
2675
metabase
cve-2023-38646
arbitrary command execution
security vulnerability
authentication bypass
nvd

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.899 High

EPSS

Percentile

98.8%

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server’s privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

Affected configurations

NVD
Node
metabasemetabaseRange<0.43.7.2-
OR
metabasemetabaseRange<1.43.7.2enterprise
OR
metabasemetabaseRange0.44.00.44.7.1-
OR
metabasemetabaseRange0.45.00.45.4.1-
OR
metabasemetabaseRange0.46.00.46.6.1-
OR
metabasemetabaseRange1.44.01.44.7.1enterprise
OR
metabasemetabaseRange1.45.01.45.4.1enterprise
OR
metabasemetabaseRange1.46.01.46.6.1enterprise

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.899 High

EPSS

Percentile

98.8%