CVE-2022-39360

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase now blocks password reset for all users who use SSO for their Metabase login.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
References () https://github.com/metabase/metabase/commit/edadf7303c3b068609f57ca073e67885d5c98730 - Patch, Third Party Advisory () https://github.com/metabase/metabase/commit/edadf7303c3b068609f57ca073e67885d5c98730 - Patch, Third Party Advisory
References () https://github.com/metabase/metabase/security/advisories/GHSA-gw4g-ww2m-v7vc - Third Party Advisory () https://github.com/metabase/metabase/security/advisories/GHSA-gw4g-ww2m-v7vc - Third Party Advisory

Information

Published : 2022-10-26 19:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-39360

Mitre link : CVE-2022-39360

CVE.ORG link : CVE-2022-39360


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-287

Improper Authentication

CWE-304

Missing Critical Step in Authentication