Lucene search

K
osvGoogleOSV:CVE-2023-38646
HistoryJul 21, 2023 - 3:15 p.m.

CVE-2023-38646

2023-07-2115:15:10
Google
osv.dev
16
metabase
arbitrary command execution
server privilege

AI Score

8.1

Confidence

High

EPSS

0.889

Percentile

98.8%

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server’s privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

AI Score

8.1

Confidence

High

EPSS

0.889

Percentile

98.8%