Exploited Vulnerabilities Daily
🌐 English

Home › Metabase

CVE-2021-41277: Metabase Metabase

EPSS97.1%No. 301 of 1739 in KEV
CVE year2021~3 yrs before listing
Same vendor in KEV2
Same product2
FieldValue
VendorMetabase
ProductMetabase
NameMetabase GeoJSON API Local File Inclusion Vulnerability
Added to KEV2024-11-12
US federal due date2024-12-03
Ransomware useUnknown
CWECWE-200

CISA description

Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-72898Metabase Metabase2026-08-1119.0%Unknown

NVD — CVE-2021-41277

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Metabase Metabase vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12.