Improper access control in Metabase - CVE-2024-55951

 

Improper access control in Metabase - CVE-2024-55951

Published: December 16, 2024 / Updated: May 5, 2026


Vulnerability identifier: #VU130154
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-55951
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in field filter value caching when handling sandboxed dashboard filters. A remote user can access a dashboard with field filters to disclose sensitive information.

This only affects Metabase Enterprise instances with sandboxing configurations created in the affected release range, and user interaction is required.


Affected software

Metabase

How to mitigate CVE-2024-55951

Install security update from vendor's website.

Metabase - update to 1.52.2.5

External References

Related Security Bulletins