6 ms·
Tell HN: Upgrade your Metabase installation
- Dachande663 3y agoPerhaps a naive question, but if running metabase within a docker container, what permissions would this RCE have? AFAIK the container has network access and access to the mounted volumes and that's it right?
- throwaway6734 3y agoIt depends on how the container is being run and if it has root Access
- hiatus 3y agoThe container has access to whatever database you connect metabase to for BI. If the db connection credentials are available to the container, it's possible a malicious actor could access your prod db.
- JJJollyjim 3y agoPresumably the metabase instance also has credentials to access some databases, some of which may be have enough privileges to also get RCE on the database machines (as well as messing with the data they hold).
- Dachande663 3y agoWe issue separate read-only credentials for database access fortunately. Still doesn't remove the risk of all the data been exfiltrated though.
- riadsila 3y agoFor more context: https://www.metabase.com/blog/security-advisory https://www.metabase.com/blog/security-advisory
- vxNsr 3y agoThey say they’ll be releasing the patch publicly, but isn’t this OSS, can’t anyone just do a diff and with a little “elbow grease” find the patch?
- MuffinFlavored 3y agohttps://github.com/metabase/metabase/compare/v0.46.6...v0.46.6.1 https://github.com/metabase/metabase/compare/v0.46.6...v0.46... I can't tell if that's it? edit: I've looked at it a few times, I don't think that's it?
- panki27 3y agoThe only thing that seems remotely interesting is the "private key" part - I don't know Clojure but it doesn't seem like that's it.
- MuffinFlavored 3y agoThey backported it to v0.45x and those changes don't seem to be included: https://github.com/metabase/metabase/compare/v0.45.4...v0.45.4.1 https://github.com/metabase/metabase/compare/v0.45.4...v0.45... aka, It isn't checked in to source control publicly yet. Interesting. I tried to "decompile" the jars and loop over the files but it didn't yield much/wasn't clean enough to be of help.
- JJJollyjim 3y agoThey haven't released the source, and the compiled versions are non-trivial to diff (e.g. there are nondeterministic numbers from the clojure compiler that seem to have changed from one to the other, and .clj files have been removed from the jar). The old version has `hash=1bb88f5`, which is a public commit: https://github.com/metabase/metabase/commit/1bb88f5 https://github.com/metabase/metabase/commit/1bb88f5 Whereas the new version has `hash=c8912af`, which is not: https://github.com/metabase/metabase/commit/c8912af https://github.com/metabase/metabase/commit/c8912af
- kevincox 3y agoThis is why I try to put everything behind NGINX with basic auth. Unfortunately not everything works well that way but in this case I suspect that this is made unexploitable by anyone without the password.
- nullcipher 3y agoor vpn
- tedeh 3y agoHa, I was just about to go in here and say the same thing. "Fortunately" some "white hat" hacker contacted us last year about another Metabase exploit. I gave him a 30 USD tip and ended up doing exactly what you are suggesting. Now I'm glad that means I don't need to interrupt my vacation to fix this thing right now.
- fuomag9 3y agoHere in Italy you get lucky if the company is not suing you :(
- konschubert 3y agoEDIT: I misunderstood.
- selimco 3y agoWe have the same https://www.zeit.de/digital/datenschutz/2021-08/cdu-connect-app-it-sicherheit-lilith-wittmann-forscherin-klage https://www.zeit.de/digital/datenschutz/2021-08/cdu-connect-...
- konschubert 3y agoI thought gp was talking abhobt their employer suing them for bugs they created.
- 3y ago
- thomasfromcdnjs 3y agoIt would be nice to know if this vulnerability affects people who never made their Metabase installations publicly accessible. Aka if I am running Metabase locally.
- deleted 3y ago[deleted]
- MuffinFlavored 3y agoHow would an attacker exploit that?
- ac2u 3y agoA vulnerability (not necessarily this one, just hypothesising) could be exploited via a payload result from an outbound request to the internet.
- MuffinFlavored 3y agoI thought when the OP of this comment thread said locally they meant like, it isn't exposed to the Internet
- ac2u 3y ago"exposed" as a word does a lot of heavy lifting here. When someone is asking me casually "hey, is this server exposed to the public internet"? I take it to mean "can someone connect to it in an inbound manner from the public internet?" If the answer is no, it doesn't necessarily mean that packets don't have other ways of making their way to the server, for example, a service running locally could have a webhook mechanism that fires events to an internet-accessible server whenever certain events happen. You might trust the services you're sending requests to as part of that, but they could become compromised and send exploits as a response. Other vulnerabilities could be services running locally but that reach out to the internet to check for updates... more surface area to exploit. If the OP was asking "I'm running this locally and I've set up my machine and firewalls to disallow any packets outside of the loopback interface", then the risk of the unpatched server is certainly reduced, but they could still be affected by another piece of software running on the same machine with internet access that is compromised first. Anything beyond an isolated machine with 100% air-gapping is theoretically at risk. Doesn't mean that the OP's question was a bad question or anything, they can use the answer to know how quickly they should worry about patching based on their own situation and risk tolerance.
- formerly_proven 3y ago> Extremely severe. An unauthenticated attacker can run arbitrary commands with the same privileges as the Metabase server on the server you are running Metabase on. Java deserialization strikes another one down, I assume?
- lecha 3y agoHow many of you have received this notice via an official security advisory channel you're monitoring/acting on? If so, which advisory service do you use and how you configure it? Learning about HN is useful, but far from a reliable solution.
- Mandatum 3y agoSaw it on HN.
- deleted 3y ago[deleted]
- not_your_vase 3y agoIt is definitely not announced on Full Disclosure nor on oss-security mailing lists.
- worthless-trash 3y agoDoesn't look like there is a CVE either: https://www.cvedetails.com/vulnerability-list/vendor_id-19475/product_id-51231/year-2023/Metabase-Metabase.html https://www.cvedetails.com/vulnerability-list/vendor_id-1947...
- capableweb 3y ago> Will you release any information about the vulnerability? > Yes, we’ll be releasing the patch publicly, as well as a CVE and an explanation in two weeks. We’re delaying release to give our install base a bit of extra time before this is widely exploited. From their blog.
- ungamedplayer 3y agoOh absolutely, but its trivial to get a CVE from the relevant CNA's. A webform or a phone call. Its a bit silly.
- theanonymousone 3y agoWill it still be (as) dangerous if Metabase is running inside a container?
- Mandatum 3y agoTo all the data inside of it? Sure. To all of the auth tokens and user creds? Why not.
- exabrial 3y agothank you!
- hannofcart 3y agoOne of the better decisions we took at my firm was to not allow direct access to any production DB to analytics visualization tools like Metabase and Redash. Always write your analytics data to a separate DB in a periodically run job. Only store aggregated anonymized data in the analytics DB you expose to internal stakeholders via tools like Metabase.
- 98codes 3y agoExactly right -- we do all of that, and even then tightly control and audit who has access to the anonymized, aggregated, read-only data cube.
- namaria 3y agoThat's a great idea and it articulates something I have thought about the whole "use boring tech" things (which I support). It doesn't preclude letting people use the shiny new thing. You can always let them plug it in and use it. But the core of the system should be as simple as possible and based on thoroughly understood tech (from the point of view of the team in question/accessible labor market).
- nucleardog 3y agoI tend to discuss things in terms of the trunk, branch, and leaves. Mostly in that the leaves of your system (parts that nothing else connects to or builds on) are generally a low risk place to try new things sometimes. If you do run into any intractable issues, it’s also an easy spot to pluck it off and replace it.
- jimmytucson 3y agoAlso your production database is optimized for different workloads than your analytics database. Usually production is used for fetching and updating a small number of records at a time (think updating a shopping cart), and has strict latency requirements whereas analytics involves reading a large amount of data in columns (think count group by one or two columns), and can be done in batches where the results can get a more and more stale until the next batch runs.
- not_your_vase 3y agoEmergency deployment late Friday afternoon (by EU time, at least), the best way to end a week :)
- kmitz 3y agoThanks for the heads up ! Without your message I'd probably have found out in a couple months :)
- jacob_rezi 3y agoWhat would happen if a software's database was completely accessible via an open api end point?
- exabrial 3y agoI think it's important to review the term "Zero Trust" because so many companies are getting it wrong. Zero Trust does not mean: "No mor VPNs and private IP network ranges, everything is public. ::elitist hipster noises::" Zero Trust simply means: "Just _because_ you're on a private network [or coming from a known ip], doesn't mean you're authenticated." You should have every single one of your internal network services (like Metabase) behind a VPN like Wireguard or numerous other options. The sole purpose of this is to reduce your firewall log noise to a manageable level that can be reviewed by hand if necessary. Obviously this isn't perfect security, but that's the _entire_ point: every security researcher says security should be an onion, not a glass sphere; many layers of independent security.
- smithcoin 3y agoIf I have my metabase installation protected behind oauth with G suite am I protected from these kinds of vectors?