CVE-2022-24853 - CVE House
Back to Database
Status published Medium CVE-2022-24853

File system exposure in Metabase

Vulnerability Description

Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our GeoJSON support. While we do validation to not return contents of arbitrary URLs, there is a case where a particularly crafted request could result in file access on windows, which allows enabling an `NTLM relay attack`, potentially allowing an attacker to receive the system password hash. If you use Windows and are on this version of Metabase, please upgrade immediately. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24853

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

metabase
Vulnerable Versions:
>= 1.40.0, < 1.40.7, >= 0.40.0, < 0.40.7, >= 1.41.0, < 1.41.6, >= 0.41.0, < 0.41.6, >= 1.42.0, < 1.42.3, >= 0.42.0, < 0.42.3

Timeline

Official Publish: April 14th, 2022
Last Modified: April 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)