Executive brief
Metabase contains a local file inclusion (LFI) vulnerability in its custom GeoJSON map support. Due to a lack of URL validation when adding custom maps, an unauthenticated attacker can read local files and environment variables.
Affected products
- Metabase Metabase 0.40.0 to 0.40.4, 1.40.0 to 1.40.4
Timeline
- 2021-11-17: disclosed: Original GitHub advisory publication date (implied by CVE year and patch history)
- 2024-11-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-12: exploited: Confirmed active exploitation in the wild per CISA KEV entry.
- 2021-11-17: patched: Fixed in versions 0.40.5 and 1.40.5