KEVIntel
10.0
CVSS
Critical

CVE-2021-41277

PUBLISHED

GeoJSON URL validation can expose server files and environment variables to unauthorized users

Exploited in the wild Remote Low complexity No user interaction
Vendor
metabase
Product
metabase
Published
Nov 17, 2021
EPSS

Description

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

cisa nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 10.0 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Exploitation status

Exploited in the wild

Recorded 2024-11-12 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Nov 12, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

chengling-ing/CVE-2021-41277

github · Created 2022-03-11 06:39:38 UTC · 1 stars

MetaBase 任意文件读取

sasukeourad/CVE-2021-41277_SSRF

github · Created 2022-01-10 01:52:10 UTC · 4 stars

CVE-2021-41277 can be extended to an SSRF

zer0yu/CVE-2021-41277

github · Created 2021-12-06 08:52:32 UTC · 9 stars

Vulnmachines/Metabase_CVE-2021-41277

github · Created 2021-11-23 18:01:23 UTC · 4 stars

z3n70/CVE-2021-41277

github · Created 2021-11-22 18:06:11 UTC · 5 stars

simple program for exploit metabase

tahtaciburak/CVE-2021-41277

github · Created 2021-11-21 11:38:08 UTC · 11 stars

PoC for CVE-2021-41277

Seals6/CVE-2021-41277

github · Created 2021-11-21 11:04:44 UTC · 9 stars

Metabase任意文件读取漏洞批量扫描工具

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nessus

  • Added to KEVIntel

  • Detected by Nuclei