V-Help
← All news
Security

Critical Vulnerability in Metabase: Customer Data Theft Attacks

Critical Vulnerability in Metabase: Customer Data Theft Attacks

Photo: BleepingComputer

Quick answer

A critical SQL injection vulnerability in Metabase (CVSS 10.0) was actively exploited by hackers to steal customer data.

Metabase, the developer of a popular business intelligence platform, disclosed a critical SQL injection (SQLi) vulnerability actively exploited by hackers in attacks targeting customer instances. The flaw, which lacks a CVE identifier, received the highest severity rating (CVSS 10.0) and allowed unauthorized attackers to gain administrative access to systems.

The issue impacted both Metabase Cloud and self-hosted deployments starting from version 1.58. The company has already released patches for all vulnerable branches (0.58–0.63) and automatically updated cloud customers. Organizations using self-hosted versions are urged to install updates immediately and conduct a security audit: revoke active user sessions, verify API keys and admin accounts for unauthorized changes, and reset database connection credentials.

Affected organizations include laptop manufacturer Framework and online form service Tally. Framework confirmed customer data theft, including names, emails, IP addresses, payment details, and corporate data. Tally reported that attackers accessed user email addresses and password hashes but not form content. LexisNexis also warned clients about a cyberattack on a third-party vendor that impacted its Metabase API.

Metabase recommends temporarily blocking access to the `/api/session/reset_password` endpoint for organizations unable to update immediately. The company also noted that attacks can be detected via specific log entries, helping identify compromised systems.

Common questions

Which Metabase versions were vulnerable?
The vulnerability affected Metabase versions from 1.58 and above, including all releases up to 0.63. Patches are available for versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.
What data could be stolen in these attacks?
Attackers could access customer personal data, including names, emails, IP addresses, payment details, password hashes, and connected database information. Some corporate clients had business data like VAT and EIN numbers compromised.
How can I check if my system was compromised?
Metabase recommends searching logs for POST requests to `/api/session/reset_password` with a 400 response code, followed by a successful GET request to `/api/user/current`. Such entries indicate a likely breach.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer