Medium severity6.5NVD Advisory· Published Oct 26, 2022· Updated Jun 17, 2026
CVE-2022-39360
CVE-2022-39360
Description
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase now blocks password reset for all users who use SSO for their Metabase login.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/metabase/metabase/commit/edadf7303c3b068609f57ca073e67885d5c98730nvdPatchThird Party Advisory
- github.com/metabase/metabase/security/advisories/GHSA-gw4g-ww2m-v7vcnvdThird Party Advisory
News mentions
0No linked articles in our index yet.