Hi Metabase team & everyone,
may i know if the free version of metabase also affected by this vulnerability or just the paid/pro/ee version?
thank you, and have a nice day
Hi Metabase team & everyone,
may i know if the free version of metabase also affected by this vulnerability or just the paid/pro/ee version?
thank you, and have a nice day
The version numbers in the advisory are for paid versions, so it doesn’t affect OSS unless its an oversight. Its possible the database registration flow mentioned only exists in paid.
OSS does have H2 and previous advisories have applied to it, mainly the one where you can send interpreted commands through the connection string. At that time it was recommended to discontinue use of H2.
hi, noted, currently im using v0.55.7
so i’m safe for this vulnerability (i hope)
thank you for your help =)
Please upgrade, we included a security center in newer versions just for users to be aware of cases like this
Security Center is an EE feature…
There are security vulnerabilities active for that version, plus 0.55 is very old.
hi, is it this one? or there are more?
thank you