Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius. The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users..

darkreading.com reported on a vulnerability with documented exploitation in production environments. The vulnerability affects systems that run the affected software version. Unpatched systems remain exposed to remote code execution or privilege escalation, depending on the specific CVE. The attack vector determines which systems are reachable.

This vulnerability represents a security issue with documented exploitation in production environments. The severity depends on the attack vector, affected systems, and exposure level. Public disclosure typically accelerates exploitation by threat actors who do not follow coordinated disclosure practices. The impact extends to any organization running the affected software version without compensating controls or network segmentation.

Source: darkreading.com

By Allan