VDB
CVE-2023-38646
CVE-2023-38646
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
EPSS 98.68% · 99.9th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
98.68%
99.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| metabase | metabase | 0.44.0, 0, 0.45.0 |
| n/a | n/a | * |
Timeline
- CVE Published
- Jul 22, 2023 EPSS Score
- Jul 28, 2023 Nuclei Template
- Jul 28, 2023 Fix Commit
- Aug 1, 2023 PoC Published
- Aug 2, 2023 PoC Published
- Aug 9, 2023 PoC Published
- Aug 9, 2023 EPSS Score
- Aug 9, 2023 PoC Published
- Aug 25, 2023 EPSS Score
- Oct 23, 2023 EPSS Score
- Nov 2, 2023 EPSS Score
References
- Nuclei Template exploit
- https://github.com/metabase/metabase/releases/tag/v0.46.6.1 url
- https://www.metabase.com/blog/security-advisory url
- https://news.ycombinator.com/item?id=36812256 url
- https://github.com/metabase/metabase/issues/32552 url
- http://packetstormsecurity.com/files/174091/Metabase-Remote-Code-Execution.html url
- http://packetstormsecurity.com/files/177138/Metabase-0.46.6-Remote-Code-Execution.html url
- https://nvd.nist.gov/vuln/detail/CVE-2023-38646 advisory