Skip to content
COOEY

EXPOSURES › CVE-2021-41277

CVE-2021-41277

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-41277 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatcheddata-breach

Metabase's GeoJSON API allows attackers to read arbitrary local files via local file inclusion.

This vulnerability enables attackers to read sensitive files on the server by exploiting the GeoJSON API's lack of input validation. For DIB organizations, this poses a significant data exposure risk if Metabase is used for sensitive data handling, requiring immediate patching and input validation review.

Shame score — A known local file inclusion vulnerability that allows reading sensitive files but does not enable remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.