Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2021-41277
PUBLISHEDGeoJSON URL validation can expose server files and environment variables to unauthorized users
- Vendor
- metabase
- Product
- metabase
- Published
- Nov 17, 2021
- EPSS
- —
Description
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Exploitation status
Exploited in the wild
Recorded 2024-11-12 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Nov 12, 2024 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41277.yaml | Apr 25, 2025 |
| Nessus | https://www.tenable.com/plugins/nessus/163589 | Mar 08, 2023 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2022-01-10 01:52:10 UTC · 4 stars
CVE-2021-41277 can be extended to an SSRF
github · Created 2021-12-06 08:52:32 UTC · 9 stars
github · Created 2021-11-23 18:01:23 UTC · 4 stars
github · Created 2021-11-22 18:06:11 UTC · 5 stars
simple program for exploit metabase
github · Created 2021-11-21 11:38:08 UTC · 11 stars
PoC for CVE-2021-41277
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nessus
-
Added to KEVIntel
-
Detected by Nuclei