S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41277 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in Metabase affects v. 0.x before 0.40.5 and 1.x before 1.40.5.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-41277
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
metabaseby metabase
< 0.40.5
metabaseby metabase
AFFECTED< 0.40.5SAFE ✓≥ 0.40.5
metabaseby metabase
AFFECTED< 0.40.5SAFE ✓≥ 0.40.5
Updated Aug 21, 2026View on NVD →
Detail

Metabase is a popular open source data analytics platform that enables individuals and organizations to easily make sense of complex data by creating custom dashboards and reports. It is designed to provide access to data from a variety of sources, including spreadsheets, databases, APIs, and AWS services. The platform is used by businesses of all sizes, from small startups to large enterprises, as well as individuals who want to better understand their personal data.

CVE-2021-41277 is a recently discovered security vulnerability in Metabase that affects the custom GeoJSON map feature. The vulnerability has been found in all versions of Metabase prior to the latest maintenance release (0.40.5 and 1.40.5). It arises from a failure to properly validate URLs before loading them, which can result in local file inclusion, including environment variables. This could allow a malicious actor to access sensitive information or execute malicious code on the affected system.

If exploited, this vulnerability can lead to significant security breaches, including data theft and system compromise. Attackers could potentially gain access to sensitive data, such as user credentials or proprietary information. In addition, they could use the system to launch additional attacks against other systems on the same network.

As an added benefit, the pro features of the s4e.io platform can help individuals and organizations quickly and easily identify vulnerabilities in their digital assets. By providing advanced scanning and analysis capabilities, this platform allows users to stay one step ahead of potential security threats and protect their valuable data. By emphasizing the importance of proactively addressing security vulnerabilities like CVE-2021-41277, organizations can ensure the ongoing safety and security of their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Upgrading to the latest maintenance release of Metabase (0.40.5 and 1.40.5).
  • Implementing a validation filter on reverse proxies or load balancers/WAFs in front of Metabase.
  • Ensuring that URLs are properly validated and sanitized before being loaded.
  • Disabling the custom GeoJSON map feature if it is not required.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.