Impact
Metabase is vulnerable when it accepts GeoJSON URLs containing the unspecified address 0.0.0.0. This omission allows an attacker to insert a malicious GeoJSON entry that points to the loopback interface; when the application subsequently fetches the data, it performs an internal request to 0.0.0.0. The response from the loopback service is then returned to the originating client, enabling unauthenticated attackers to observe internal service output or carry out further exploitation. The weakness is a Server‑Side Request Forgery (CWE‑918).
Affected Systems
Metabase installations running any release up to and including 0.63.18 are affected. The vulnerability is present in the open‑source version, as indicated by the vendor/product identification. No other specific product variants or versions are listed in the release notes provided.
Risk and Exploitability
The CVSS score is 6.9 and the EPSS score is below 1%; it is not in the CISA KEV catalog. The attack requires no authentication and can be performed through the GeoJSON API, which the data suggests is the intended attack path. The likely attack vector is an unauthenticated HTTP request that creates or modifies a GeoJSON entry pointing to 0.0.0.0. The low exploitation probability indicates limited active exploitation in the wild, but the mechanism remains straightforward.
OpenCVE Enrichment