Feed/CVE-2023-38646
CVE-2023-38646CRITICALCVSS 9.8

CVE-2023-38646

Published Jul 21, 2023·Updated Jun 17, 2026

NVD Description

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

Public Exploits & PoCs40 found

PoC: metabase-pre-auth-rce-poc

This is a script written in Python that allows the exploitation of the Metabase's software security flaw described in CVE-2023-38646.

22

PoC: MetabaseRceTools

CVE-2023-38646 Metabase RCE

5

PoC: CVE-2023-38646

CVE-2023-38646 (Pre-Auth RCE in Metabase)

1

PoC: CVE-2023-38646-POC

CVE-2023-38646-POC

1

PoC: CVE-2023-38646

Metabase Pre-auth RCE (CVE-2023-38646)!!

1

PoC: POC_Metabase_CVE-2023-38646

For educational purposes only

1

PoC: metabase-cve-2023-38646

Repo contains the PoC and steps to reproduce cve 2023-38646

PoC: Metabase-Pre-Auth-RCE-POC

CVE-2023-38646

PoC: cve-2023-38646-poc

CVE-2023-38646是Metabase中的一个远程代码执行漏洞。该漏洞源于Metabase在处理未经身份验证的API端点/api/setup/validate时,对JDBC连接字符串的处理存在安全缺陷。攻击者可以通过构造特定的JDBC连接字符串,利用该端点在服务器上执行任意命令,而无需进行身份验证。

PoC: CVE-2023-38646-PoC-Metabase

Proof-of-Concept script for exploiting CVE-2023-38646. Intended for educational and research purposes only.

PoC: cve-2023-38646-poc

CVE-2023-38646是Metabase中的一个远程代码执行漏洞。该漏洞源于Metabase在处理未经身份验证的API端点/api/setup/validate时,对JDBC连接字符串的处理存在安全缺陷。攻击者可以通过构造特定的JDBC连接字符串,利用该端点在服务器上执行任意命令,而无需进行身份验证。

PoC: CVE-2023-38646

Exploit for CVE-2023-38646, a pre-auth RCE in Metbase

PoC: CVE-2023-38646

CVE-2023-38646 Metabase 0.46.6 exploit

PoC: Exploit-CVE-2023-38646-Metabase

Exploit for the Remote Code Execution (RCE) vulnerability identified in Metabase versions before 0.46.6.1 (open source) and 1.46.6.1 (Enterprise). Authentication is not required for exploitation.

PoC: Another-Metabase-RCE-CVE-2023-38646

Metabase postgres (org.h2.Driver) RCE without INIT

PoC: CVE-2023-38646

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

PoC: CVE-2023-38646

Code to detect/exploit vulnerable metabase application

PoC: CVE-2023-38646

Metabase Pre-Auth RCE POC

PoC: CVE-2023-38646-Crapsploit

A crappy exploit script written for CVE-2023-38646. It works about as well as peace treaties between Israel and Hamas.

PoC: CVE-2023-38646

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

PoC: CVE-2023-38646

Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection

PoC: CVE-2023-38646

RCE Exploit for CVE-2023-38646

PoC: CVE-2023-38646

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

PoC: CVE-2023-38646

Exploit script for Pre-Auth RCE in Metabase (CVE-2023-38646)

PoC: CVE-2023-38646

This is a Proof of Concept (PoC) script for exploiting Metabase, an open-source business intelligence and data analytics tool.

PoC: CVE-2023-38646

CVE-2023-38646 Unauthenticated RCE vulnerability in Metabase

PoC: CVE-2023-38646

CVE-2023-38646 Metabase 0.46.6 exploit

PoC: Metabase-H2-CVE-2023-38646-

Metabase H2 远程代码执行漏洞(CVE-2023-38646)

PoC: CVE-2023-38646

CVE-2023-38646 Pre-Auth RCE in Metabase

PoC: CVE-2023-38646

Metabase Pre-auth RCE (CVE-2023-38646)

PoC: CVE-2023-38646

Automatic Tools For Metabase Exploit Known As CVE-2023-38646

PoC: CVE-2023-38646-PoC

Metabase Pre-auth RCE

PoC: CVE-2023-38646

Proof of Concept for CVE-2023-38646

PoC: CVE-2023-38646

Tools to exploit metabase CVE-2023-38646

PoC: CVE-2023-38646

POC for CVE-2023-38646

PoC: CVE-2023-38646-glwax

Remote Code Execution on Metabase CVE-2023-38646

PoC: CVE-2023-38646

Remote Code Execution on Metabase CVE-2023-38646

PoC: CVE-2023-38646-suynl

Metabase pre-auth RCE PoC

PoC: CVE-2023-38646-hmoje

Proof of Concept for CVE-2023-38646

PoC: CVE-2023-38646

Proof of Concept for CVE-2023-38646

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free