Loading
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
Use Metabase vendor hub and Metabase product page to widen CVE-2023-38646 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-37470, CVE-2022-39362 and CVE-2022-39361 for nearby disclosures in the same product family.