Input validation error in Metabase - #VU130128

 

Input validation error in Metabase - #VU130128

Published: December 12, 2021 / Updated: May 5, 2026


Vulnerability identifier: #VU130128
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper input validation in the custom GeoJSON map feature when processing specially encoded URLs. A remote user can supply a specially encoded URL to disclose sensitive information.

The issue is only exploitable through administrator access to the custom maps setting.


Affected software

Metabase

Remediation

Install security update from vendor's website.

Metabase - addressed in versions 0.38.6, 0.39.6, 0.40.6, 0.41.3.1, 1.38.6, 1.39.6, 1.40.6, 1.41.3.1

External References

Related Security Bulletins