First published: Sat Jan 28 2023(Updated: )
Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. Sandboxed users shouldn't be able to view data about other Metabase users anywhere in the Metabase application. However, when a sandbox user views the settings for a dashboard subscription, and another user has added users to that subscription, the sandboxed user is able to view the list of recipients for that subscription. This issue is patched in versions 0.43.7.1, 1.43.7.1, 0.44.6.1, 1.44.6.1, 0.45.2.1, and 1.45.2.1. There are no workarounds.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metabase | <0.43.7.1 | |
Metabase | >=0.44.0<0.44.6.1 | |
Metabase | >=0.45.0<0.45.2.1 | |
Metabase | >=1.0.0<1.43.7.1 | |
Metabase | >=1.44.0<1.44.6.1 | |
Metabase | >=1.45.0<1.45.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23628 is a vulnerability that allows unauthorized actors to view sensitive information in Metabase.
CVE-2023-23628 affects certain versions of Metabase and allows sandboxed users to view data about other users.
CVE-2023-23628 has a severity level of medium (4.1).
To fix CVE-2023-23628, update Metabase to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-23628 in the Metabase security advisory on GitHub.