CVE-2022-39359
Severity CVSS v4.0:
Pending analysis
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
26/10/2022
Last modified:
28/10/2022
Description
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable `MB_CUSTOM_GEOJSON_ENABLED` was also added to disable custom GeoJSON completely (`true` by default).
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 0.41.0 (including) | 0.41.9 (excluding) |
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 0.42.0 (including) | 0.42.6 (excluding) |
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 0.43.0 (including) | 0.43.7 (excluding) |
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 0.44.0 (including) | 0.44.5 (excluding) |
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 1.41.0 (including) | 1.41.9 (excluding) |
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 1.42.0 (including) | 1.42.6 (excluding) |
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 1.43.0 (including) | 1.43.7 (excluding) |
| cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* | 1.44.0 (including) | 1.44.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



