216.73.216.233

CVE-2023-38646

· Published 21/07/2023 17:15 · Modified 21/12/2025 02:44 · Author: The MITRE Corporation

Labels: CVE-2023-38646

Essential information

Published
21/07/2023 17:15
Modified
21/12/2025 02:44
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

NVD status

NVD
View on NVD