Junglewise Threat Intelligence

CVE-2021-41277: Metabase GeoJSON API Local File Inclusion Vulnerability

CVE-2021-41277 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2024-11-12

Executive brief

Metabase contains a local file inclusion (LFI) vulnerability in its custom GeoJSON map support. Due to a lack of URL validation when adding custom maps, an unauthenticated attacker can read local files and environment variables.

Affected products

  • Metabase Metabase 0.40.0 to 0.40.4, 1.40.0 to 1.40.4

Timeline

  • 2021-11-17: disclosed: Original GitHub advisory publication date (implied by CVE year and patch history)
  • 2024-11-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-12: exploited: Confirmed active exploitation in the wild per CISA KEV entry.
  • 2021-11-17: patched: Fixed in versions 0.40.5 and 1.40.5

Related threats