Skip to content

Comment on Tell HN: Upgrade your Metabase installationparent

Comments

Will you release any information about the vulnerability?
Yes, we’ll be releasing the patch publicly, as well as a CVE and an explanation in two weeks. We’re delaying release to give our install base a bit of extra time before this is widely exploited.

From their blog.

Oh absolutely, but its trivial to get a CVE from the relevant CNA's. A webform or a phone call.

Its a bit silly.

Don't you have to share more details about the exploit then? That seems to be the thing they're trying to avoid for now.

Negative, you can request a CVE without specific details, CNA's do this all the time until unembargo.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.