Metabase Zero-Day Exploited in Wild for Admin Access Without Authentication

A high-severity security flaw in the business intelligence and data visualization software package has been exploited in the wild, compromising the integrity of Metabase systems worldwide. The vulnerability, which affects all supported versions, does not require authentication for an attacker to gai

Metabase has issued an alert warning users of the vulnerability, which has been exploited by attackers in the wild. The flaw, rated at a maximum CVSS score of 10.0, represents a critical risk to the security of Metabase systems.

Experts warn that the vulnerability can be exploited by attackers using a variety of techniques, including exploiting a weakness in the software's authentication mechanism. This allows an attacker to bypass the system's authentication requirements and gain full administrative access to the system without providing any login credentials.

Metabase advises users to update to the latest version of the software immediately to mitigate the risk of exploitation. However, in the absence of a CVE identifier, it is unclear whether a patch has been developed or released. As a result, users are advised to exercise caution and monitor their systems for signs of unauthorized access.

Metabase's vulnerability disclosure policy states that it will not publicly disclose the details of the vulnerability until a patch has been developed and released. This policy is in line with industry best practices, which emphasize the importance of responsible disclosure and collaboration with vendors to address security vulnerabilities.

As of March 11, 2023, the vulnerability has been identified in multiple systems, with reports of unauthorized access to administrative accounts. Experts warn that the attack vector could be used by attackers to spread malware or gain access to sensitive data.

Users are advised to remain vigilant and take immediate action to secure their systems, as the vulnerability remains unpatched and the risk of exploitation continues to grow.

Metabase has not commented publicly on the incident, but its security advisory has provided users with essential information to mitigate the risk of exploitation. By taking proactive steps to secure their systems, users can help prevent unauthorized access and protect their data from potential threats.

Source: The Hacker News