Critical Zero-Day SQL Injection Unleashes Data Theft Against Metabase Cloud and Self-Hosted Deployments

A severe, previously unknown SQL injection vulnerability within the Metabase data analytics platform has been actively exploited in real-world attacks, leading to unauthorized access and significant data exfiltration from numerous customer instances, affecting both managed cloud services and independently hosted environments.

Metabase, a widely adopted open-source business intelligence tool enabling organizations to create dashboards and reports from their data, recently confirmed that a sophisticated zero-day exploit targeted its infrastructure. This critical flaw, identified as an unauthenticated SQL injection vulnerability, granted attackers administrative privileges over compromised Metabase instances. The ramifications were immediate and profound, with customer data theft confirmed across several high-profile victims. The incident underscores the inherent risks associated with managing critical data infrastructure and the persistent threat of zero-day exploits in complex software ecosystems.

Understanding the Vulnerability: A Deep Dive into the SQL Injection Flaw

The disclosed vulnerability is an unauthenticated SQL injection, a class of security flaw consistently ranked among the most dangerous by organizations like OWASP. SQL injection occurs when an attacker can insert malicious SQL code into input fields, tricking the application’s database into executing commands beyond its intended scope. In this specific Metabase scenario, the flaw was unauthenticated, meaning an attacker did not require legitimate user credentials to initiate the exploit. This significantly broadens the attack surface and reduces the barriers to entry for malicious actors.

Upon successful exploitation, the vulnerability provided remote attackers with full administrator access to a customer’s Metabase instance. The implications of such access are catastrophic. With administrator privileges, an attacker could:

  • Alter application configuration: Manipulate settings, potentially creating backdoors or disabling security features.
  • Steal stored credentials: Access sensitive login information for connected databases, which Metabase uses to pull and analyze data. This could lead to lateral movement into an organization’s primary data stores.
  • Read any data accessible through connections: Directly query and exfiltrate all data that Metabase has access to, which often includes highly sensitive operational, financial, and customer information.
  • Export data: Leverage Metabase’s legitimate data export functionalities to rapidly extract large volumes of compromised information.

Metabase’s internal assessment assigned this flaw a maximum CVSS score of 10.0, indicating the highest possible severity. This score reflects the ease of exploitation (unauthenticated, remote) and the devastating impact (complete compromise of data and system control). While a formal Common Vulnerabilities and Exposures (CVE) identifier was not immediately assigned, the security advisory explicitly confirmed active exploitation, highlighting the urgency of the situation.

Timeline of Exploitation and Metabase’s Response

The initial exploitation was identified on August 3rd, with Metabase disclosing the attacks and warning its user base on August 6th. This rapid response time from detection to public disclosure, while commendable, still left a window for attackers to operate unseen. Metabase confirmed that its Metabase Cloud SaaS platform was directly compromised through this previously unknown vulnerability, affecting versions 1.58 and above. Crucially, the company also alerted that self-hosted installations were equally vulnerable, placing the onus on individual organizations to secure their deployments.

Upon discovering the breach, Metabase implemented a multi-pronged response strategy:

Metabase SQLi zero-day exploited in customer data-theft attacks
  1. Endpoint Blocking: Immediately blocked the specific endpoints leveraged by attackers to prevent further exploitation.
  2. Rapid Patch Development: Developed and rolled out a fix for the vulnerability across all affected branches.
  3. Cloud Customer Remediation: Proactively upgraded and patched all Metabase Cloud customer instances, mitigating the immediate threat for its managed service users.
  4. Advisory and Guidance: Issued comprehensive security advisories and detailed instructions for self-hosted customers, including patching information and post-compromise forensic steps.

Affected Versions and Critical Remediation Steps

The SQL injection vulnerability impacted Metabase versions 1.58 through 0.63. To address the flaw, Metabase released patched versions across all affected branches. The minimum safe releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. Organizations running any version within the vulnerable range are strongly advised to upgrade to these or newer safe versions without delay.

For organizations managing self-hosted Metabase installations, the responsibility for applying these critical updates falls entirely on their internal IT or security teams. Metabase Cloud customers benefited from automatic patching, underscoring a key advantage of SaaS models in rapid incident response.

Recognizing that immediate patching might not always be feasible for complex enterprise environments, Metabase provided an interim mitigation strategy. Organizations unable to upgrade instantly were advised to temporarily block access to the /api/session/reset_password endpoint. This specific endpoint was identified as the vector for the SQL injection, and restricting access could prevent further exploitation while a full update is prepared and deployed.

Post-Compromise Actions and Indicators of Compromise (IoCs)

Beyond patching, Metabase strongly recommended a series of post-incident actions for self-hosted customers to ascertain the extent of compromise and secure their environments:

  • Revoke All Active User Sessions: This invalidates any active sessions, including those potentially hijacked by attackers.
  • Review API Keys and Administrator Accounts: Scrutinize these critical assets for any unauthorized changes, additions, or suspicious activity.
  • Rotate Credentials for Connected Databases: Given that attacker access could lead to the theft of database credentials, rotating these is paramount to prevent further lateral movement.
  • Inspect Logs and Query History: Thoroughly examine Metabase system logs and query history for any signs of unusual or unauthorized activity.

To aid in identifying potential compromises, Metabase provided specific indicators of compromise (IoCs). Organizations should look for system logs showing a POST request to /api/session/reset_password that returns a 400 status code, immediately followed by a successful GET request to /api/user/current. This sequence is indicative of a successful exploit and subsequent access verification by the attacker. Any logs matching this pattern should be treated as confirmed evidence of a breach.

Confirmed Data Theft Incidents: A Glimpse into the Impact

The zero-day exploitation quickly translated into tangible data breaches for several organizations leveraging Metabase. Three prominent cases highlight the varied impact and the sensitive nature of the data exposed.

Framework: The innovative laptop manufacturer, Framework, confirmed that its Metabase instance was compromised, leading to the theft of customer information. In a breach notification to its customers, Framework detailed the scope of the stolen data, which included full names, email addresses, login IP addresses, billing and shipping address information, phone numbers, and company names. For their "Framework for Business" clientele, additional data such as VAT numbers, EINs, and billing email addresses were also exposed. This incident represents a significant exposure of Personally Identifiable Information (PII), potentially leading to identity theft, phishing attacks, and other forms of fraud against Framework customers. The company was notified by Metabase on August 6th, confirming the compromise that had occurred on August 3rd.

Metabase SQLi zero-day exploited in customer data-theft attacks

Tally: The popular online form builder, Tally, also reported a breach of its Metabase analytics environment on August 3rd. Attackers gained access to user email addresses and password hashes. While Tally emphasized that the passwords were stored as "cryptographic hashes" and were "one-way" (meaning they couldn’t be directly reversed into plain text), the exposure of hashes still poses a significant risk. Weak or unsalted hashes can be susceptible to brute-force attacks or rainbow table lookups, especially if users reused simple passwords. Tally clarified that user forms and submitted answers, which often contain sensitive data, were stored separately and were not compromised in this incident, limiting the scope of the data breach. The specific hashing algorithm and salting practices employed by Tally remain undisclosed, which is crucial for assessing the true risk associated with the exposed hashes.

LexisNexis: In a demonstration of the cascading effects of supply chain vulnerabilities, LexisNexis, a global provider of legal, regulatory, and business information, informed its customers of a cyberattack impacting one of its third-party vendors. While not explicitly naming Metabase, LexisNexis confirmed that its "Metabase API" was affected. The company identified "unusual activity on servers that are hosted and managed by a third-party vendor" and proactively disconnected from these systems to contain the issue. This necessary containment action resulted in service disruptions for applications like Diligence, Metabase API, and Newsdesk. The full extent of data exposure in the LexisNexis incident is still under investigation with the assistance of a cybersecurity forensic firm. This case highlights how a vulnerability in one component of the software supply chain can ripple through to impact multiple downstream clients, even if they are not directly running the vulnerable software themselves.

Broader Implications and Future Outlook

The Metabase zero-day exploitation serves as a stark reminder of several critical cybersecurity challenges.

Firstly, the persistent danger of zero-day vulnerabilities underscores the need for continuous security monitoring, threat intelligence, and robust incident response capabilities. Even well-maintained software can harbor undiscovered flaws, and attackers are constantly seeking to exploit these windows of opportunity.

Secondly, the incident highlights the inherent risks of critical data analytics platforms. Metabase, by its very nature, connects to and processes vast amounts of potentially sensitive organizational data. A compromise of such a platform provides attackers with a direct conduit to an organization’s crown jewels.

Thirdly, the case of LexisNexis illustrates the pervasive and complex issue of supply chain security. Organizations are not only responsible for securing their own infrastructure but also for vetting and continuously monitoring the security posture of their third-party vendors and the software components they utilize. A single point of failure in a vendor’s system can have widespread repercussions for their clients.

Finally, the exposure of hashed passwords (as seen with Tally) reinforces the importance of strong cryptographic practices including the use of robust, modern hashing algorithms combined with unique, cryptographically strong salts for each password. This is a fundamental defense against offline password cracking attempts.

Moving forward, organizations must prioritize timely patching, implement comprehensive security monitoring with a focus on anomalous activity, and develop detailed incident response plans that account for zero-day exploits and supply chain risks. Regular security audits, penetration testing, and the adoption of a "assume breach" mindset are essential to navigate the evolving threat landscape. The Metabase incident underscores that even widely trusted tools can become vectors for attack, necessitating vigilance and proactive defense at every layer of the enterprise IT ecosystem.

Related Posts

Critical Metabase SQL Injection Zero-Day Unleashes Widespread Customer Data Exfiltration

A severe SQL injection flaw within the widely adopted Metabase analytics platform has been actively exploited as a zero-day vulnerability, enabling unauthorized access to customer instances and leading to significant…

Sophisticated Cyber Extortion Rings Leverage Vishing and Cloud Vulnerabilities to Infiltrate Elite Financial Institutions

A sophisticated and evolving wave of cyberattacks has been meticulously traced to UNC6671, a persistent and aggressive extortion syndicate. This group, which previously operated under the "BlackFile" moniker, has been…

Leave a Reply

Your email address will not be published. Required fields are marked *