Missing SQL permissions check in metabase
CVE-2023-32680
What is CVE-2023-32680?
Metabase, an open-source business analytics engine, suffers from a critical access control vulnerability. The affected versions failed to enforce required group permissions for editing SQL snippets, allowing users—including those with restricted access in sandboxed groups—to manipulate SQL queries. This means that an unauthorized individual could alter a SQL snippet that controlled their data visibility, potentially gaining elevated access to sensitive information. It is recommended that users upgrade to the latest versions of Metabase or restrict SQL queries used in creating sandboxes to ensure security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
metabase < 0.44.7 < 0.44.7
metabase >= 1.0.0, < 1.44.7 < 1.0.0, 1.44.7
metabase >= 0.45.0, < 0.45.4 < 0.45.0, 0.45.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
