Local Link Access Protection Circumvention in Metabase by Metabase Inc.
CVE-2025-30371

2.1LOW

Key Information:

Vendor

Metabase

Status
Vendor
CVE Published:
28 March 2025

What is CVE-2025-30371?

Metabase, a popular business intelligence tool, has a vulnerability that allows circumvention of local link access protection on the GeoJson endpoint. This issue affects self-hosted instances of Metabase that utilize the GeoJson feature, especially when these instances are not isolated from other unsecured resources. It poses a risk of unauthorized access to sensitive information stored within these systems. The problem is resolved in versions v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Users are encouraged to upgrade to these patched versions or consider migrating to Metabase Cloud for enhanced security. Alternatively, deploying Metabase in a dedicated subnet with strict outbound port controls can help mitigate the risks associated with this vulnerability.

Affected Version(s)

metabase < 0.52.16.4 < 0.52.16.4

metabase < 1.52.16.4 < 1.52.16.4

metabase < 0.53.8 < 0.53.8

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.