EXPOSURES › CVE-2021-41277
CVE-2021-41277
HIGH ⌖ ON CISA KEV · EXPLOITEDMetabase's GeoJSON API allows attackers to read arbitrary local files via local file inclusion.
This vulnerability enables attackers to read sensitive files on the server by exploiting the GeoJSON API's lack of input validation. For DIB organizations, this poses a significant data exposure risk if Metabase is used for sensitive data handling, requiring immediate patching and input validation review.
Shame score — A known local file inclusion vulnerability that allows reading sensitive files but does not enable remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.