CVE-2022-43776: SSRF
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Metabase vulnerability?
The vulnerability ID of this Metabase vulnerability is CVE-2022-43776.
What is the title of this Metabase vulnerability?
The title of this Metabase vulnerability is "The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks."
How can this vulnerability be exploited?
This vulnerability can be exploited by utilizing the url parameter of the /api/geojson endpoint in Metabase versions <44.5 to perform Server Side Request Forgery attacks.
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.5.
How can this vulnerability be fixed?
To fix this vulnerability, it is recommended to update Metabase to version 44.5 or higher.