CVE List

CVE-2022-43776

Moderate 6.5

The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.

Published October 26, 2022.

Affected software

Get alerts for Metabase Metabase

Reference links