← Back

CVE-2022-39360

nvd nist
Published: Oct 26, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase now blocks password reset for all users who use SSO for their Metabase login.

Affected (8)

Products: Metabase: Metabase
1 product
Metabase
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Metabase
From 0.41.0 to 0.41.9
From 0.42.0 to 0.42.6
From 0.43.0 to 0.43.7
From 0.44.0 to 0.44.5
From 1.41.0 to 1.41.9
From 1.42.0 to 1.42.6
From 1.43.0 to 1.43.7
From 1.44.0 to 1.44.5

References (4)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.