Lucene search

K
cvelistMitreCVELIST:CVE-2023-38646
HistoryJul 21, 2023 - 12:00 a.m.

CVE-2023-38646

2023-07-2100:00:00
mitre
www.cve.org
1
metabase
security vulnerability
arbitrary commands
exploitation
privilege escalation
authentication

10 High

AI Score

Confidence

High

0.899 High

EPSS

Percentile

98.8%

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server’s privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

10 High

AI Score

Confidence

High

0.899 High

EPSS

Percentile

98.8%