Metabase zero-day SQL injection flaw actively exploited in customer data thefts

A critical SQL injection vulnerability in Metabase versions 1.58 and above has been actively exploited to breach customer instances and steal data, Metabase disclosed on Thursday. The unauthenticated flaw gives attackers administrator access to instances, allowing them to steal credentials, read databases and export data. Metabase Cloud customers have been patched; self-hosted users must upgrade immediately to versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5.
Laptop maker Framework confirmed attackers used the vulnerability to steal customer names, email addresses, billing and shipping addresses, phone numbers and login IP addresses. The flaw carries a CVSS score of 10.0 and has not yet been assigned a CVE identifier. Metabase advises customers to revoke user sessions, rotate database credentials, and review logs for POST requests to /api/session/reset_password followed by GET requests to /api/user/current, which indicate compromise, Mayank Parmar reports for BleepingComputer.