Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "BCD50540-E323-41CE-9D9C-EDA8CB718E42", "versionEndExcluding": "0.41.9", "versionStartIncluding": "0.41.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "EF01C7BF-CB4C-4990-9082-587CFD555225", "versionEndExcluding": "0.42.6", "versionStartIncluding": "0.42.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "8858058E-C597-4752-8625-9B279DC65A48", "versionEndExcluding": "0.43.7", "versionStartIncluding": "0.43.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "6A94F7EA-BC18-4013-9A93-7962226FDD98", "versionEndExcluding": "0.44.5", "versionStartIncluding": "0.44.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "804B84E1-5D1A-4251-9829-65F5FD927D99", "versionEndExcluding": "1.41.9", "versionStartIncluding": "1.41.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "73310924-8CD4-4696-89B9-EED3390375A6", "versionEndExcluding": "1.42.6", "versionStartIncluding": "1.42.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "A86AA0C8-2C4F-4DDD-8371-6B43611E2479", "versionEndExcluding": "1.43.7", "versionStartIncluding": "1.43.0", "vulnerable": true}, {"criteria": "cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*", "matchCriteriaId": "EF7A60F6-5062-4094-91A5-71445F9B7BC1", "versionEndExcluding": "1.44.5", "versionStartIncluding": "1.44.0", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Execution (RCE), which can be abused by users able to write SQL queries on H2 databases. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer allows DDL statements in H2 native queries."}, {"lang": "es", "value": "Metabase es un software de visualizaci\u00f3n de datos. En versiones anteriores a 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9 y 1.41.9, H2 (base de datos de muestra) pod\u00eda permitir una ejecuci\u00f3n de c\u00f3digo remota (RCE), de la que pod\u00edan abusar los usuarios capaces de escribir consultas SQL en las bases de datos H2. Este problema est\u00e1 parcheado en versiones 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9 y 1.41.9. Metabase ya no permite las sentencias DDL en las consultas nativas H2"}], "id": "CVE-2022-39361", "lastModified": "2024-11-21T07:18:07.077", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "security-advisories@github.com", "type": "Secondary"}, {"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2022-10-26T19:15:14.707", "references": [{"source": "security-advisories@github.com", "tags": ["Third Party Advisory"], "url": "https://github.com/metabase/metabase/security/advisories/GHSA-gqpj-wcr3-p88v"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory"], "url": "https://github.com/metabase/metabase/security/advisories/GHSA-gqpj-wcr3-p88v"}], "sourceIdentifier": "security-advisories@github.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-20"}, {"lang": "en", "value": "CWE-441"}], "source": "security-advisories@github.com", "type": "Secondary"}, {"description": [{"lang": "en", "value": "NVD-CWE-noinfo"}], "source": "nvd@nist.gov", "type": "Primary"}]}