CVE-2021-41277 - CVE House
Back to Database
Status published Critical CVE-2021-41277

GeoJSON URL validation can expose server files and environment variables to unauthorized users

Vulnerability Description

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-41277

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

metabase
Vulnerable Versions:
< 0.40.5, >= 1.0.0, < 1.40.5

Timeline

Official Publish: November 17th, 2021
Last Modified: October 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Weaknesses (CWE)