A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting versions 1.58 and above.
Vulnerability Details
The company warns that self-hosted installations are also vulnerable. The vulnerability is an unauthenticated SQL injection flaw in Metabase that can ultimately give a remote attacker administrator access to a customer's instance. Metabase has not assigned the vulnerability a CVE identifier, but its security advisory rates it as Critical with a CVSS score of 10.0 and confirms that it has been actively exploited.
According to Metabase's security advisory, this is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Impact on Customers
Metabase is available both as software that organizations can host themselves and through Metabase Cloud, the company's managed SaaS offering. Metabase says its Cloud customers have already been upgraded and patched, while organizations running vulnerable self-hosted installations must update manually. The SQLi vulnerability has been fixed in patched versions for all affected branches from 0.58 through 0.63, with the minimum safe releases being 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.
Organizations unable to upgrade immediately are advised to temporarily block access to the '/api/session/reset_password' endpoint until the update can be applied. Metabase recommends that self-hosted customers immediately upgrade, revoke all active user sessions, review API keys and administrator accounts for unauthorized changes, rotate credentials for connected databases, and inspect logs and query history for signs of compromise.
Attacks on Framework and Tally
Customers disclose Metabase data theft attacks. Laptop maker Framework is one of the companies that has confirmed customer information was stolen after attackers compromised its Metabase instance. In a breach notification sent to customers and shared with BleepingComputer, Framework said the incident allowed the attackers to steal customer information. The stolen data includes full names, email addresses, login IP addresses, billing and shipping address information, phone number, and company name.
Tally, the popular online form builder, has also notified users that its Metabase analytics environment was compromised on August 3. Through that, they reached your email address, and your password as a cryptographic hash. A hash is one-way, so it can't be turned back into your password. They didn't reach your forms, or the answers people submitted to them. Those are stored separately.
Other Affected Companies
LexisNexis is warning customers that it was impacted by a cyberattack at one of its third-party vendors. While the company did not specifically state it was linked to the Metabase API, it did say its Metabase API was impacted by the attack.
According to an email shared with BleepingComputer, LexisNexis said, We are writing to provide an update on the service disruption affecting Diligence, Metabase API and Newsdesk. Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor. To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.
LexisNexis said taking the systems offline caused the affected applications to become unavailable, but it was necessary while the company investigated. It is unclear whether customer data was exposed during the attack, but the company says it is working with a cybersecurity forensic firm to investigate the incident.
Conclusion
The Metabase SQL injection vulnerability is a critical issue that has been actively exploited, resulting in data theft attacks on multiple companies. It is essential for organizations to take immediate action to protect themselves, including upgrading to the latest version, revoking active user sessions, and reviewing API keys and administrator accounts for unauthorized changes.
Source: BleepingComputer