Description
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
Published: 2023-07-21
Score: 9.8 Critical
EPSS: 94.3% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Metabase Metabase
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T17:46:56.432Z

Reserved: 2023-07-21T00:00:00.000Z

Link: CVE-2023-38646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-21T15:15:10.003

Modified: 2024-11-21T08:13:58.837

Link: CVE-2023-38646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses