---
cve: "CVE-2023-38646"
severity: "LOW"
cvss: 3.1
epss: "98.7%"
vendor: "n/a"
kev: false
exploited: false
published: "2023-07-21 15:15:10"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T07:12:00+02:00"
---

# CVE-2023-38646

> 3.1 LOW · 🧪 PoC

## Beschreibung

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

## Patch verfügbar (OSV)

- 8e08caecb420474f379fc2035e89dbdae44b5ca6 (Commit)
- 5154d762e28f5047b5a308a5bca59d3f97ee987f (Commit)

## Referenzen

- <https://www.metabase.com/blog/security-advisory>
- <https://github.com/metabase/metabase/releases/tag/v0.46.6.1>
- <https://news.ycombinator.com/item?id=36812256>
- <https://github.com/metabase/metabase/issues/32552>
- <http://packetstormsecurity.com/files/174091/Metabase-Remote-Code-Execution.html>
- <http://packetstormsecurity.com/files/177138/Metabase-0.46.6-Remote-Code-Execution.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-38646) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
