Lucene search

K
osvGoogleOSV:CVE-2022-43776
HistoryOct 26, 2022 - 6:15 p.m.

CVE-2022-43776

2022-10-2618:15:11
Google
osv.dev
5
cve-2022-43776
url parameter
ssrf vulnerability
metabase
version 44.5

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.9%

The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.9%

Related for OSV:CVE-2022-43776