Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase now blocks password reset for all users who use SSO for their Metabase login.
History

Thu, 24 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-10-26T00:00:00.000Z

Updated: 2025-04-23T16:42:39.520Z

Reserved: 2022-09-02T00:00:00.000Z

Link: CVE-2022-39360

cve-icon Vulnrichment

Updated: 2024-08-03T12:00:44.174Z

cve-icon NVD

Status : Modified

Published: 2022-10-26T19:15:13.657

Modified: 2024-11-21T07:18:06.940

Link: CVE-2022-39360

cve-icon Redhat

No data.