Metabase Information Disclosure Vulnerability (CVE-2021-41277)

Description

What is the attack?

FortiGuard Labs observes widespread attack attempts targeting a three-year-old Metabase vulnerability (CVE-2021-41277) detected by more than 30,000 sensors. Successful exploitation could lead to information disclosure including expose server files and environment variables to unauthorized users. The vulnerability occurs due to the use of user-supplied input without proper validation.

Metabase is an open-source data analytics platform. According to their website it is used by over 60,000 companies including, Capital One, OpenAI, and more. FortiGuard Recon Threat Intelligence team tracked this vulnerability being targeted by a hacktivist group called GhostSec back in May 2024.

What is the recommended Mitigation?

This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that (including x.41+). GitHub

What FortiGuard Coverage is available?

  • FortiGuard recommends users to apply the patch and follow any mitigation steps provided by the vendor if not done already.

  • FortiGuard IPS protection "Metabase.GeoJSON.Path.Traversal" is available to detect and block any attack attempts.

  • The FortiGuard Incident Response team can be engaged to help with any suspected compromise.