VYPR

apk package

chainguard/metabase-oci-entrypoint

pkg:apk/chainguard/metabase-oci-entrypoint

Vulnerabilities (5)

  • CVE-2026-72898CriKEVAug 10, 2026
    affected < 0.63.2-r1fixed 0.63.2-r1

    Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

  • CVE-2026-33725HigMar 27, 2026
    affected < 0fixed 0

    Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and Arbitrar

  • CVE-2026-22805HigJan 12, 2026
    affected < 0fixed 0

    Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. This vulnerability is fixed in

  • CVE-2023-37470CriAug 4, 2023
    affected < 0fixed 0

    Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue is

  • CVE-2023-38646CriJul 21, 2023
    affected < 0fixed 0

    Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1