CVE-2023-23628: Metabase subject to Exposure of Sensitive Information to an Unauthorized Actor
Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. Sandboxed users shouldn't be able to view data about other Metabase users anywhere in the Metabase application. However, when a sandbox user views the settings for a dashboard subscription, and another user has added users to that subscription, the sandboxed user is able to view the list of recipients for that subscription. This issue is patched in versions 0.43.7.1, 1.43.7.1, 0.44.6.1, 1.44.6.1, 0.45.2.1, and 1.45.2.1. There are no workarounds.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23628?
CVE-2023-23628 is a vulnerability that allows unauthorized actors to view sensitive information in Metabase.
How does CVE-2023-23628 affect Metabase?
CVE-2023-23628 affects certain versions of Metabase and allows sandboxed users to view data about other users.
What is the severity level of CVE-2023-23628?
CVE-2023-23628 has a severity level of medium (4.1).
How can I fix CVE-2023-23628?
To fix CVE-2023-23628, update Metabase to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-23628?
You can find more information about CVE-2023-23628 in the Metabase security advisory on GitHub.