S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-38646 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Metabase open source and Metabase Enterprise affects v. Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-38646
9.8
CVSS

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Metabase open source and Metabase Enterprise are powerful business intelligence tools utilized by numerous organizations to manage and analyze their data. The open-source version enables a user to create, visualize, and share dashboards while the enterprise version provides more advanced features such as automated reporting, single sign-on, and data caching. These tools are designed to provide greater insight into an organization's operations and improve decision-making processes.

CVE-2023-38646 is a serious vulnerability that was recently detected in both Metabase open source and Metabase Enterprise before specific versions. The vulnerability allows attackers to execute arbitrary commands on a server without needing to authenticate. This means that anyone with access to the server can exploit this vulnerability, putting the entire system at risk. Attackers can use this vulnerability to gain access to sensitive data, modify data, or even delete entire databases.

If this vulnerability is exploited, it can have severe consequences for an organization. These include data theft, financial loss, damage to the organization's reputation, and even legal penalties. Organizations that do not take immediate action to protect against this vulnerability risk exposing their operations, employees, customers, and stakeholders to these risks.

In conclusion, the CVE-2023-38646 vulnerability in Metabase open source and Metabase Enterprise is a serious issue that should be addressed immediately. By taking steps to protect against this vulnerability, organizations can protect themselves against potential cyber-attacks and data breaches. By using the pro features of the s4e.io platform, organizations can stay informed about potential vulnerabilities and take pro-active steps to secure their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take the following precautions:

  • Update to one of the fixed versions of Metabase specified in the background context.
  • Limit server access to authorized personnel only.
  • Monitor server activity for suspicious activity.
  • Enable two-factor authentication to prevent unauthorized access.
  • Regularly back up data to ensure it can be quickly restored if it is lost or corrupted.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.