Information disclosure in Metabase - CVE-2022-39359
Published: October 24, 2022 / Updated: May 5, 2026
Metabase
Metabase
Description
The vulnerability allows a remote attacker to access blocked internal network resources.
The vulnerability exists due to improper access control in custom GeoJSON map URL handling when fetching user-supplied GeoJSON URLs that respond with redirects. A remote attacker can supply a crafted GeoJSON URL to access blocked internal network resources.
The issue affects redirect handling for custom GeoJSON map URLs, including redirects to link-local or private-network addresses.