CVE-2025-30371

Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that are using the GeoJson feature could be potentially impacted if their Metabase is colocated with other unsecured resources. This is fixed in v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Migrating to Metabase Cloud or redeploying Metabase in a dedicated subnet with strict outbound port controls is an available workaround.
CVSS

No CVSS.

Configurations

No configuration.

History

28 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 15:15

Updated : 2025-03-28 18:11


NVD link : CVE-2025-30371

Mitre link : CVE-2025-30371

CVE.ORG link : CVE-2025-30371


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')