Skip to content

Possible to circumvent Locked parameter in Signed Embedding

Critical
ranquild published GHSA-8qgm-9mj6-36h3 Oct 24, 2022

Package

Metabase OSS and Enterprise (Metabase)

Affected versions

<x.44.5,<x.43.7,<x.42.6

Patched versions

0.44.5,1.44.5,0.43.7,1.43.7,0.42.6,1.42.6

Description

Impact

It was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious request to the backend.

Patches

The following patches (or greater versions) are available:

  • 0.44.5 and 1.44.5,
  • 0.43.7 and 1.43.7,
  • 0.42.6 and 1.42.6

All releases are available on https://github.com/metabase/metabase/releases.

Severity

Critical

CVE ID

CVE-2022-39358

Weaknesses