One of the better decisions we took at my firm was to not allow direct access to any production DB to analytics visualization tools like Metabase and Redash. Always write your analytics data to a separate DB in a periodically run job. Only store aggregated anonymized data in the analytics DB you expose to internal stakeholders via tools like Metabase.
Tell HN: Upgrade your Metabase installation
41–50 of 76 posts
Re: Tell HN: Upgrade your Metabase installation
#42How many of you have received this notice via an official security advisory channel you're monitoring/acting on? If so, which advisory service do you use and how you configure it? Learning about HN is useful, but far from a reliable solution.
It is definitely not announced on Full Disclosure nor on oss-security mailing lists.
Re: Tell HN: Upgrade your Metabase installation
#43Earlier quoted context omitted.
They say they’ll be releasing the patch publicly, but isn’t this OSS, can’t anyone just do a diff and with a little “elbow grease” find the patch?
> Yes, we’ll be releasing the patch publicly, as well as a CVE and an explanation in two weeks. We’re delaying release to give our install base a bit of extra time before this is widely exploited.
Re: Tell HN: Upgrade your Metabase installation
#44Earlier quoted context omitted.
> Yes, we’ll be releasing the patch publicly, as well as a CVE and an explanation in two weeks. We’re delaying release to give our install base a bit of extra time before this is widely exploited.
Unfortunately that means it's not possible to deploy this without violating the AGPL...
Re: Tell HN: Upgrade your Metabase installation
#45Earlier quoted context omitted.
Ha, I was just about to go in here and say the same thing. "Fortunately" some "white hat" hacker contacted us last year about another Metabase exploit. I gave him a 30 USD tip and ended up doing exactly what you are suggesting. Now I'm glad that means I don't need to interrupt my vacation to fix this thing right now.
Here in Italy you get lucky if the company is not suing you :(
Re: Tell HN: Upgrade your Metabase installation
#46This is why I try to put everything behind NGINX with basic auth. Unfortunately not everything works well that way but in this case I suspect that this is made unexploitable by anyone without the password.
Re: Tell HN: Upgrade your Metabase installation
#47Earlier quoted context omitted.
Here in Italy you get lucky if the company is not suing you :(
EDIT: I misunderstood.
https://www.zeit.de/digital/datenschutz/2021-08/cdu-connect-...
Re: Tell HN: Upgrade your Metabase installation
#48Earlier quoted context omitted.
> Yes, we’ll be releasing the patch publicly, as well as a CVE and an explanation in two weeks. We’re delaying release to give our install base a bit of extra time before this is widely exploited.
Unfortunately that means it's not possible to deploy this without violating the AGPL...
Re: Tell HN: Upgrade your Metabase installation
#49One of the better decisions we took at my firm was to not allow direct access to any production DB to analytics visualization tools like Metabase and Redash. Always write your analytics data to a separate DB in a periodically run job. Only store aggregated anonymized data in the analytics DB you expose to internal stakeholders via tools like Metabase.
Re: Tell HN: Upgrade your Metabase installation
#50Earlier quoted context omitted.
Here in Italy you get lucky if the company is not suing you :(
EDIT: I misunderstood.
- https://www.golem.de/news/connect-app-cdu-verklagt-offenbar-... - https://www.heise.de/news/Modern-Solution-Anklage-gegen-Aufd...