1 article with this tag
Unauthenticated SQL injection in the Metabase password-reset endpoint (CWE-89, CVSS 10.0, KEV). Upgrade to the patch for your release line. But the key point is that a BI tool holds the credentials for every database it connects to, so this site's position is that the response is only complete once sessions are revoked and the credentials of every connected database have been rotated.