Metabase SQLi zero-day exploited in customer data-theft attacks
According to BleepingComputer, a Metabase SQL injection zero-day vulnerability was exploited in customer data-theft attacks. The attacks were disclosed by Framework and Tally, two companies that appear to have been affected. The source does not specify the exact version of Metabase affected, the nature of the data stolen, or the number of customers impacted. It also does not provide technical details about the vulnerability or the attack methodology. The disclosure highlights that the vulnerability was actively exploited in the wild, underscoring the risk to organizations using Metabase. The source does not include any remediation steps or recommendations, nor does it mention whether patches were available at the time of disclosure. The incident serves as a reminder of the ongoing threat posed by zero-day vulnerabilities in widely used open-source tools.
Metabase users face active exploitation of a zero-day SQLi vulnerability, risking customer data theft.