VDB

CVE-2023-38646

CVE-2023-38646 PUBLISHED CVSS 9.800000190734863 CRITICAL

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

EPSS 98.68% · 99.9th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
98.68%
99.9th percentile

Affected Products

VendorProductVersions
metabasemetabase0.44.0, 0, 0.45.0
n/an/a*

Timeline

  • CVE Published
  • Jul 22, 2023 EPSS Score
  • Jul 28, 2023 Nuclei Template
  • Jul 28, 2023 Fix Commit
  • Aug 1, 2023 PoC Published
  • Aug 2, 2023 PoC Published
  • Aug 9, 2023 PoC Published
  • Aug 9, 2023 EPSS Score
  • Aug 9, 2023 PoC Published
  • Aug 25, 2023 EPSS Score
  • Oct 23, 2023 EPSS Score
  • Nov 2, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›