← Back

CVE-2023-38646

Published: Jul 21, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

Affected (8)

Products: Metabase: Metabase
1 product
Metabase
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Metabase
Before 0.43.7.2
From 0.44.0 to 0.44.7.1
From 0.45.0 to 0.45.4.1
From 0.46.0 to 0.46.6.1
Before 1.43.7.2
From 1.44.0 to 1.44.7.1
From 1.45.0 to 1.45.4.1
From 1.46.0 to 1.46.6.1

References (12)

Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.