CVE-2023-38646: Critical severity Metabase vulnerability
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Metabase open sourceto a version that resolves this vulnerability.Fixed in 0.46.6.1 - Upgrade
Upgrade
Metabase Enterpriseto a version that resolves this vulnerability.Fixed in 1.46.6.1
Event History
Frequently Asked Questions
What is the vulnerability ID for this Metabase vulnerability?
The vulnerability ID for this Metabase vulnerability is CVE-2023-38646.
What is the severity of CVE-2023-38646?
The severity of CVE-2023-38646 is critical with a severity value of 9.8.
How can attackers exploit CVE-2023-38646?
Attackers can exploit CVE-2023-38646 to execute arbitrary commands on the server, at the server's privilege level without requiring authentication.
What software versions are affected by CVE-2023-38646?
Metabase open source versions before 0.46.6.1 and Metabase Enterprise versions before 1.46.6.1 are affected by CVE-2023-38646.
How can I fix CVE-2023-38646?
To fix CVE-2023-38646, you should update your Metabase installation to version 0.46.6.1 for open source or 1.46.6.1 for Metabase Enterprise.