Impact
Metabase, an open‑source business intelligence platform, exposes a flaw that allows an authenticated administrator to craft H2 database connection properties that bypass input validation and execute arbitrary Java code on the server. The vulnerability is a form of code injection, reflected in CWE‑94, and leads to full compromise of confidentiality, integrity, and availability for installations that are running affected versions 1.55.0 through 1.58.15.0.
Affected Systems
Affected systems: Metabase, the open‑source business intelligence platform. The flaw exists in installations running Metabase versions from 1.55.0 through 1.58.15.0 inclusive. Versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2 contain the fix and are therefore not vulnerable.
Risk and Exploitability
The CVSS score of 9.1 classifies the issue as critical. The EPSS score indicates a low probability of exploitation, yet the lack of a CISA KEV listing does not reduce its severity. Exploitation requires an authenticated administrator who can register a crafted H2 connection, after which attacker‑controlled Java code runs with the server’s privileges.
OpenCVE Enrichment