Skip to content

CVE-2021-41277

Exposure of Sensitive Information — is CVE-2021-41277real, exploitable, or a false positive? Here's the community ground truth.

Critical · CVSS 10EPSS 96.9%CISA KEVCWE-200 · Exposure of Sensitive Information
Affected:Metabase

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

Published

Embed this verdict
TruePositive verdict for CVE-2021-41277
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2021-41277/badge.svg)](https://www.truepositive.app/cve/CVE-2021-41277)
HTML
<a href="https://www.truepositive.app/cve/CVE-2021-41277"><img src="https://www.truepositive.app/cve/CVE-2021-41277/badge.svg" alt="TruePositive verdict for CVE-2021-41277"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

3 verdicts
Not a real issue

Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.

to add your verdict.

Community real-world severity: Critical (Critical 3) — CVSS base score 10

In line with its CVSS base score.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

  • 0
    Field note · Priya NairCurated

    Confirmed exploited in the wild — listed in the CISA KEV catalog (added 2024-11-12). Treat as real and prioritize patching over triage.

Same weaknessCWE-200 · Exposure of Sensitive Information.