CVE-2023-23629

MEDIUM
Published Jan 28, 20233y ago · Modified Jun 17, 20261w ago
6.3 CVSS 3.1
Medium
Find Similar
Published Jan 28, 2023 3y ago
Last Modified Jun 17, 2026 1w ago

Description

Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This allows someone with greater access to data to create a dashboard subscription, add people with fewer data privileges, and all recipients of that subscription receive the same data: the charts shown in the email would abide by the privileges of the user who created the subscription. The issue is users with fewer privileges who can view a dashboard are able to add themselves to a dashboard subscription created by someone with additional data privileges, and thus get access to more data via email. This issue is patched in versions 0.43.7.1, 1.43.7.1, 0.44.6.1, 1.44.6.1, 0.45.2.1, and 1.45.2.1. On Metabase instances running Enterprise Edition, admins can disable the "Subscriptions and Alerts" permission for groups that have restricted data permissions, as a workaround.

CVSS Details

Base Score
6.3
Exploitability
2.1
Impact
4.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity Low
Availability None

Threat Intelligence

No active exploitation signals — not in CISA KEV and no EPSS score yet.

Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 2

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Information Exposure
CWE-269 Improper Privilege Management Authorization

Affected Products 6

VendorProductVersionRange
metabasemetabase* <0.43.7.1
metabasemetabase*≥0.44.0  –  <0.44.6.1
metabasemetabase*≥0.45.0  –  <0.45.2.1
metabasemetabase*≥1.0.0  –  <1.43.7.1
metabasemetabase*≥1.44.0  –  <1.44.6.1
metabasemetabase*≥1.45.0  –  <1.45.2.1

References 1

  • github.com https://github.com/metabase/metabase/security/advisories/GHSA-ch8f-hhq9-7gv5
    Third Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.