๐จ ACTIVE EXPLOITATION
- UPDATE: Metabase SQL Injection Zero-Day Exploited to Steal Customer Data
Attackers exploited a Metabase SQL injection zero-day to access customer data.
- Metabase Cloud and self-hosted deployments on versions 0.58 through 0.63 were affected; Framework and Tally confirmed exposure.
- The unauthenticated SQL injection flaw was rated CVSS 10.0 and could grant administrator access to Metabase instances.
- Attackers could steal connected-database credentials, read accessible data, and export it.
- Vulnerable branches were fixed in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.
- The attack pattern was POST /api/session/reset_password returning 400, followed by GET /api/user/current returning 200; Framework reported exposed names, emails, addresses, phone numbers, and login IPs. ๐ Coverage: mastodon.social ยท ๐ via @campuscodi@mastodon.social