Metabase의 심각한 보안 취약점이 악용되어 인증 없이 관리 접근이 가능함.
Metabase는 비즈니스 인텔리전스 및 데이터 시각화 소프트웨어에서 최대 심각도의 보안 취약점이 악용되었다고 경고했습니다. 이 취약점(CVSS 점수: 10.0)은 CVE 식별자가 없으며, 인증 없는 원격 공격자가 메타베이스 애플리케이션 데이터베이스에 임의의 SQL을 주입할 수 있게 합니다. 이는 관리자 접근을 허용할 수 있는 심각한 문제입니다.
A critical vulnerability in Metabase allows admin access without authentication.
Metabase has warned of a maximum-severity vulnerability impacting its business intelligence and data visualization software. This zero-day flaw (CVSS score: 10.0) has no CVE identifier and allows unauthenticated remote attackers to inject arbitrary SQL into the Metabase application database. This can potentially enable them to gain admin access, posing a significant security threat.