CVE-2022-24855

    Dashboard / Vulnerabilities / CVE-2022-24855

    CVE-2022-24855

    Published: 14 Apr 2022Last Modified: 12 Aug 2026

    Summary: XSS vulnerability in Metabase

    Details: Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links that could lead to account takeover. Users are advised to either upgrade immediately, or block access in your firewall to `/_internal` endpoints for Metabase. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 961caedc9983dfef7e25dfdfb0e18c9bde02dca4

    Affected versions

    v1.41.6
    v1.41.5
    v1.41.3.1
    v1.41.3
    v1.41.2
    v1.41.1
    v1.41.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-24855 | CVE-DB