By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Metabase SQLi Zero-Day Exploited in Customer Data Theft
A critical SQL injection vulnerability, designated as a zero-day exploit, was actively leveraged to compromise instances of Metabase, a popular open-source business intelligence tool. These attacks resulted in the theft of customer data, with specific impacts identified for organizations using Framework and Tally. The vulnerability allowed attackers to execute arbitrary SQL commands on the underlying database, bypassing intended access controls and extracting sensitive information. The exploitation of this zero-day means that no patches or defenses were publicly available at the time of the initial attacks, leaving affected systems vulnerable until the flaw was discovered and addressed.
Metabase is widely used by businesses to visualize and explore data, enabling them to make informed decisions. Its open-source nature means it is deployed in a variety of environments, from small startups to large enterprises. The breach highlights the risks associated with open-source software when critical vulnerabilities are discovered and exploited before developers can release fixes. The attackers were able to gain unauthorized access to databases connected to Metabase instances, potentially exfiltrating customer lists, financial data, or other proprietary information. The specific nature of the data stolen would depend on the database schemas and the permissions granted to the Metabase application.
The impact on Framework and Tally, while not fully detailed, indicates that these companies were among the direct targets or users whose data was compromised through their Metabase deployments. The term 'Framework' could refer to a software framework or a specific company, and 'Tally' is known for its accounting software, suggesting that financial or customer-related data might have been at risk. The exploitation of a zero-day vulnerability underscores the sophistication of threat actors and the constant need for robust security practices, including continuous monitoring and rapid incident response.
Security researchers are investigating the full scope of the attacks and the methods used by the attackers. The discovery and public disclosure of such vulnerabilities are crucial for the broader security community to develop and deploy countermeasures. Organizations relying on Metabase are advised to apply any available security patches immediately and to review their database access logs for any signs of suspicious activity. The incident serves as a stark reminder of the persistent threats posed by SQL injection attacks and the importance of securing all layers of the technology stack, from the application itself to the underlying databases and network infrastructure.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.