Metabase has warned that hackers exploited a serious SQL injection vulnerability in zero-day attacks to break into customer systems and steal data.
The company said its Metabase Cloud platform was targeted through a previously unknown flaw affecting versions 1.58 and later. Self-hosted installations are also vulnerable.
The flaw does not require authentication and can allow attackers to gain administrator access to a Metabase instance. Metabase said it blocked the attack vectors and released security updates to fix the issue.
The vulnerability has been patched in versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.
Metabase urged self-hosted customers to update as soon as possible. Organizations that cannot update right away should temporarily block access to the /api/session/reset_password endpoint.
Customers are also advised to revoke active sessions, review administrator accounts and API keys, change database credentials, and check logs and query history for signs of unauthorized access.