1 article with this tag
Unauthenticated SQL injection in the Metabase password-reset endpoint (CWE-89, CVSS 10.0, KEV). Upgrade to the patch for your release line. But the real lesson is that a BI tool is a keyring for every database behind it, so this site's position is that the response is only complete once sessions are revoked and the credentials of every connected database have been rotated.