PT-2026-94085 · Metabase+1 · Metabase
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Metabase versions prior to 0.63.19
Description
Improper validation of the unspecified address 0.0.0.0 in custom GeoJSON URLs allows unauthenticated attackers to access loopback services. An attacker can save a malicious GeoJSON entry using the address 0.0.0.0 to trigger requests that return responses from loopback services to unauthenticated callers.
Recommendations
Update to version 0.63.19 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metabase