Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in...
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in...
저장소 Security Advisory 원문에서 CVE 번호가 CVE-2026-50148와 일치하는지 먼저 확인하고, 일치할 때만 수정 버전 값(1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, 1.60.4)을 조치 기준으로 사용합니다.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 metabase 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, 1.60.4 기준을 충족하는지 확인합니다. 이어서 경로 조작·임의 파일 접근 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.