CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-30371

LOW
2.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-03-28
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that are using the GeoJson feature could be potentially impacted if their Metabase is colocated with other unsecured resources. This is fixed in v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Migrating to Metabase Cloud or redeploying Metabase in a dedicated subnet with strict outbound port controls is an available workaround.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅