Local Link Access Protection Circumvention in Metabase by Metabase Inc.
CVE-2025-30371

2.1LOW

Key Information:

Vendor

Metabase

Status
Vendor
CVE Published:
28 March 2025

What is CVE-2025-30371?

Metabase, a popular business intelligence tool, has a vulnerability that allows circumvention of local link access protection on the GeoJson endpoint. This issue affects self-hosted instances of Metabase that utilize the GeoJson feature, especially when these instances are not isolated from other unsecured resources. It poses a risk of unauthorized access to sensitive information stored within these systems. The problem is resolved in versions v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Users are encouraged to upgrade to these patched versions or consider migrating to Metabase Cloud for enhanced security. Alternatively, deploying Metabase in a dedicated subnet with strict outbound port controls can help mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

metabase < 0.52.16.4 < 0.52.16.4

metabase < 1.52.16.4 < 1.52.16.4

metabase < 0.53.8 < 0.53.8

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.