CISA Known Exploited Vulnerability

CVE-2021-41277

Metabase · Metabase

Metabase GeoJSON API Local File Inclusion Vulnerability

Date added
BOD 22-01 due date
CWE CWE-200
Ransomware Unknown

CISA description

Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.