Metabase's GeoJSON validation doesn't prevent redirects to blocked URLs
CVE-2022-39359
What is CVE-2022-39359?
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer follow redirects on GeoJSON map URLs. An environment variable MB_CUSTOM_GEOJSON_ENABLED was also added to disable custom GeoJSON completely (true by default).

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
metabase < 0.41.9 < 0.41.9
metabase >= 0.42.0, < 0.42.6 < 0.42.0, 0.42.6
metabase >= 0.43.0, < 0.43.7 < 0.43.0, 0.43.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
