CVE-2022-24853

    Dashboard / Vulnerabilities / CVE-2022-24853

    CVE-2022-24853

    Published: 14 Apr 2022Last Modified: 12 Aug 2026

    Summary: File system exposure in Metabase

    Details: Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our GeoJSON support. While we do validation to not return contents of arbitrary URLs, there is a case where a particularly crafted request could result in file access on windows, which allows enabling an `NTLM relay attack`, potentially allowing an attacker to receive the system password hash. If you use Windows and are on this version of Metabase, please upgrade immediately. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 961caedc9983dfef7e25dfdfb0e18c9bde02dca4

    Affected versions

    v1.41.6
    v1.41.5
    v1.41.3.1
    v1.41.3
    v1.41.2
    v1.41.1
    v1.41.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-24853 | CVE-DB