GobyVuls/CVE-2023-38646.md
Goby 8c78e6dbfb
Create CVE-2023-38646.md
add CVE-2023-38646
2023-07-28 14:23:14 +08:00

13 lines
1.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

## Metabase JDBC Remote Code Execution Vulnerability (CVE-2023-38646)
| **Vulnerability** | **Metabase JDBC Remote Code Execution Vulnerability (CVE-2023-38646)** |
| :----: | :-----|
| **Chinese name** | Metabase JDBC 远程代码执行漏洞CVE-2023-38646 |
| **CVSS core** | 9.8 |
| **FOFA Query** (click to view the results directly)| [title=="Metabase" \|\| ((body="<script type=\"application/json\" id=\"_metabaseBootstrap\">" \|\| body="window.MetabaseLocalization = JSON.parse(document.getElementById(\"_metabaseLocalization\").textContent);") && body="window.MetabaseRoot = actualRoot;")](https://en.fofa.info/result?qbase64=dGl0bGU9PSJNZXRhYmFzZSIgfHwgKChib2R5PSI8c2NyaXB0IHR5cGU9XCJhcHBsaWNhdGlvbi9qc29uXCIgaWQ9XCJfbWV0YWJhc2VCb290c3RyYXBcIj4iIHx8IGJvZHk9IndpbmRvdy5NZXRhYmFzZUxvY2FsaXphdGlvbiA9IEpTT04ucGFyc2UoZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoXCJfbWV0YWJhc2VMb2NhbGl6YXRpb25cIikudGV4dENvbnRlbnQpOyIpICYmIGJvZHk9IndpbmRvdy5NZXRhYmFzZVJvb3QgPSBhY3R1YWxSb290OyIp) |
| **Number of assets affected** | 66604 |
| **Description** | Metabase is an open source data analysis and visualization tool that helps users easily connect to various data sources, including databases, cloud services, and APIs, and then use an intuitive interface for data query, analysis, and visualization.A remote code execution vulnerability exists in Metabase that could allow an attacker to execute arbitrary code on a server running with Metabase server privileges. |
| **Impact** | A remote code execution vulnerability exists in Metabase that could allow an attacker to execute arbitrary code on a server running with Metabase server privileges. |
![](https://s3.bmp.ovh/imgs/2023/07/28/4a0b2c90aaf1b387.gif)