Skip to main content
CISA Known Exploited Vulnerabilities

Metabase GeoJSON API Local File Inclusion Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2024-11-12
Remediation due
2024-12-03

Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes
https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr ; https://nvd.nist.gov/vuln/detail/CVE-2021-41277

Description

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

Severity

CVSS 3.1 · CNA10 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CVSS 3.1 · CISA7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
metabasemetabase
< 0.40.5
>= 1.0.0, < 1.40.5

References

2 Links

Record Details

Published
2021-11-17
Last updated
2025-10-21
Assigner (CNA)
GitHub_M
Credited to
-

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CWE-200 · Exposure of Sensitive Information

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.