Metabase is an open source data analytics platform. In affected versions a local file inclusion security issue has been discovered with the custom GeoJSON map (admin->settings->maps->custom maps->add a map
) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded.
View the template here CVE-2021-41277.yaml
References:
https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr