home.social

#metabase — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #metabase, aggregated by home.social.

fetched live
  1. 🚨 CRITICAL ALERT: CVE-2026-72898 (CVSS 10.0)

    Unauthenticated SQL Injection in Metabase allows remote attackers to execute arbitrary SQL, hijack admin accounts & exfiltrate enterprise DB credentials. Patch immediately!

    Read full analysis: denizhalil.com/2026/08/13/cve-

    #CyberSecurity #Metabase #SQLi

  2. 7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase

    This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
    What is OpenLiteSpeed?
    OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you to ...
    Continued 👉 blog.radwebhosting.com/configu #selfhosted #debian #reverseproxy #openjdk #letsencrypt #jre #selfhosting #installguide #proxyserver #vps

  3. @wdormann
    no hashtag #metabase ?
    No metabase-account at mastodon?
    WHY??
    (I still like metabase though)

  4. Ein Zero-Day in #Metabase führte zu einem Datenleck beim Laptophersteller #Framework Kundenkontakte sowie Lieferdaten gingen verloren Zahlungs- und Bestellinformationen blieben laut Hersteller geschützt Metabase hat Updates bereitgestellt und Cloud-Instanzen gesichert heise.de/news/Durch-Metabase-0

  5. Good news: I’m learning which services use #Metabase (which I really like!) as they send out breach notifications to customers.

    Bad news: Using a third-party analytics tool can be great, but maybe don’t give it access to things like your user account tables with emails and hashed passwords (or worse)?

  6. Just got a notice that #Metabase, the "AI" powered database vendor used by #Framework, has been hacked. And my data was part of the breach 😓

    #AI is basically a swiss-cheese of easily exploitable security vulnerabilities. Shame on Framework for using them, and shame on me for trusting them with my data.

  7. Oh, nice, @frameworkcomputer got pwn'd and all the customer info (name, email, address, phone number) got stolen. Via their BI provider Metabase.

    As @Viss says, go the the cloud they said, it'll be great they said.

    Wouldn't it be awesome if the companies getting breached suffered some sort of consequences for not securing their shit? I'm willing to bet that Metabase has a huge list of exploited-in-the-wild CVEs in their infra.

    #metabase #framework #HaveIBeenPwnd

  8. for security reasons you should change your name every 6 months

    #framework #metabase

  9. > Dear Valued #Framework Customer,
    >
    > We are writing to inform you of a data breach at our business intelligence database provider #Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.

    Process personal data in SaaS => high value target

  10. 🚨 Oh look, another #data breach! This time featuring #Metabase as the unwitting sidekick in the circus act of "Oops, Your Data is Showing!" 🎪 Framework's fans are just thrilled with the speedy notification—as if that's going to stitch their #privacy back together. 🤡🔧
    community.frame.work/t/framewo #breach #Framework #notification #cybersecurity #HackerNews #ngated

  11. @frameworkcomputer sent me this email (they didn't post it on blog or fediverse):
    Notice of Limited Data Breach

    We confirmed that the following information was accessed:
        Full name
        Email address
        Login IPs
        Billing and shipping address information
            Country
            Address
            City
            State
            Zip code
            Phone number
            Company
    For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
        Company
        Phone
        VAT
        EIN
        Billing Email
    No other personally identifiable information, order information, or payment information was accessed.

    Dear Valued Framework Customer,
    We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
    We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
    We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
    What happened?
    On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
    On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
    Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
    Rotate the credentials for every database connected to your instance; and
    Review the admin accounts on your instance and remove anything you don't recognize.
    We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
    (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
    This report is based on our own application logs. We did not query or read the data in your connected databases.
    Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
    We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
    Sameer Al-Sakran Founder and CEO Metabase
    We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker.
    1/2

    #framework #breach #hack #metabase

  12. Looks like #Metabase was breached via SQL injection from an unauthenticated endpoint. I was informed because #Framework emailed me saying my data was in the database that was accessed. Framework states they were notified of the #breach August 6th.

    Metabase info: github.com/metabase/metabase/s

    What was accessed according to Framework:

    We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:

    Full name
    Email address
    Login IPs
    Billing and shipping address information
    Country
    Address
    City
    State
    Zip code
    Phone number
    Company

    For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
    Company
    Phone
    VAT
    EIN
    Billing Email

    In the notification to Framework on the 6th, Metabase stated that it was a preliminary update and they were still investigating at that time, though they say they have patched the vulnerability.

  13. Looks like #framework had a breach regarding their database provider #Metabase. I’ve never even bought anything with them. I had a reservation before but I cancelled it.

  14. 7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase

    This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
    What is OpenLiteSpeed?
    OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you ...
    Continued 👉 blog.radwebhosting.com/configu #selfhosted #openjdk #reverseproxy #jre #selfhosting #proxyserver #vps #debian #letsencrypt #installguide

  15. 7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase

    This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
    What is OpenLiteSpeed?
    OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you ...
    Continued 👉 blog.radwebhosting.com/configu #installguide #selfhosted #vps #reverseproxy #proxyserver #debian #openjdk #jre #selfhosting #letsencrypt

  16. 7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase

    This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
    What is OpenLiteSpeed?
    OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you ...
    Continued 👉 blog.radwebhosting.com/configu #openjdk #letsencrypt #reverseproxy #installguide #selfhosting #selfhosted #jre #proxyserver #vps #debian

  17. 🚀 mb-cli v0.3.0 is out — a CLI for exploring your Metabase instance.

    Highlights:
    🗂️ New `collection` commands to browse collections, cards & dashboards
    🔍 `card params` / `dashboard params list` to discover parameters before running
    ⏱️ `--timeout` flag + clean Ctrl+C cancellation
    🔑 `MB_SESSION_TOKEN` auth — no admin API key required
    📦 `go install` works out of the box
    📖 New recipes cookbook

    github.com/andreagrandi/mb-cli

    #Metabase #CLI #golang #opensource