TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Additional critical Metabase security vulnerabilities announced today

3 pointsby nfmalmost 2 years ago

2 comments

nfmalmost 2 years ago
Metabase announced a patch release for a critical vulnerability a little over a week ago: <a href="https:&#x2F;&#x2F;www.metabase.com&#x2F;blog&#x2F;security-advisory" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.metabase.com&#x2F;blog&#x2F;security-advisory</a><p>Today they have announced further, related vulnerabilities, and if you&#x27;re running your own instance you should patch again, or disable your instance until you have a chance to do so.<p>The vulnerabilities allow an unauthenticated attacker to run arbitrary commands with the same privileges as the Metabase server on the server you are running Metabase on. This would allow arbitrary querying of any database that Metabase is connected to.
exabrialalmost 2 years ago
Very important! Another update