Description
Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that are using the GeoJson feature could be potentially impacted if their Metabase is colocated with other unsecured resources. This is fixed in v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Migrating to Metabase Cloud or redeploying Metabase in a dedicated subnet with strict outbound port controls is an available workaround.
INFO
Published Date :
2025-03-28T14:47:36.718Z
Last Modified :
2025-03-28T15:42:10.181Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-30371 vulnerability.
| Vendors | Products |
|---|---|
| Metabase |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-30371.