.. / CVE-2021-41277

Exploit for Metabase - Local File Inclusion (CVE-2021-41277)

Description:

Metabase is an open source data analytics platform. In affected versions a local file inclusion security issue has been discovered with the custom GeoJSON map (admin->settings->maps->custom maps->add a map) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded.

Nuclei Template

View the template here CVE-2021-41277.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-41277.yaml
Copy

References:

https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr
https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0
https://twitter.com/90security/status/1461923313819832324
https://github.com/pen4uin/vulnerability-research-list
https://nvd.nist.gov/vuln/detail/CVE-2021-41277