A security flaw was identified within the /api/setup/validate API endpoint, a pivotal component of Metabase's initial configuration procedure. This endpoint played a vital role in verifying the database connection during application setup. However, a vulnerability existed in how it managed JDBC connections, ultimately opening the door to remote code execution (RCE) without the need for prior authentication. This allowed malicious actors to run unauthorized commands on the server with elevated permissions, effectively granting them complete authority over the application environment. This level of access could facilitate data theft, application manipulation, or even total control over the entire server infrastructure, representing a substantial threat to the system's integrity.
-----------------------------------------------------------------------
Twitter: / abhishekmorla
Website: https://abhishekmorla.netlify.app/
Linkedin: / abhishekmorla
Discord Server: / discord
------------------------------------------------------------------------