← Back

CVE-2022-24855

nvd nist
Published: Apr 14, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links that could lead to account takeover. Users are advised to either upgrade immediately, or block access in your firewall to `/_internal` endpoints for Metabase. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.

Affected (6)

Products: Metabase: Metabase
1 product
Metabase
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Metabase
From 0.40.0 to 0.40.8
From 0.41.0 to 0.41.7
From 0.42.0 to 0.42.4
From 1.40.0 to 1.40.8
From 1.41.0 to 1.41.7
From 1.42.0 to 1.42.4

References (4)

Source: security-advisories@github.com
Release NotesThird Party Advisory
Source: security-advisories@github.com
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory

Timeline

No history available yet.