Late patching of Metabase SQLi bug claims Sydney’s Mathspace

Key points

Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance following an August 7 advisory.

Late patching of Metabase SQLi bug claims Sydney's Mathspace

Late patching of Metabase SQLi bug claims Sydney's Mathspace

Key points

  • Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance following an August 7 advisory.
  • Stolen data includes user IDs, usernames, first and last names, email addresses and other login-related information for students, staff, parents and guardians.
  • Only Australian and New Zealand users were affected, and Mathspace has notified authorities including the Office of the Australian Information Commissioner and the Australian Cyber Security Centre.




Late patching of Metabase SQLi bug claims Sydney's Mathspace










A critical vulnerability in the Metabase business intelligence (BI) tool was exploited by unknown attackers to breach online mathematics learning platform Mathspace.

Although Metabase issued a security advisory on August 7, advising customers to upgrade their self-hosted installations immediately, Mathspace founder and chief technology officer (CTO) Alvin Savoy said this wasn’t done.

“Our existing vulnerability-notification process did not identify and escalate that advisory for action,” Savoy said.

“We updated our instance on August 29 after a later Metabase notice came to our attention.”

That delay in patching was enough for attackers gain access to Mathspace’s Metabase instance, and steal data.

Savoy said a range of data was taken, for students, staff and for parents and guardians.

This includes user ID, usernames, first and last names, email addresses as well as other information relating to logins.

Trivially exploitable critical SQLi bug

The Metabase vulnerability carries a maximum severity rating of 10.0 out of 10 possible, and is easy to exploit.

It allows structured query language (SQL) command injection through the /api/session/reset_password page and allows a remote attacker to gain administrator access to the Metabase instance without providing any credentials.

A wide range of Metabase versions are affected by the vulnerability, from x.58.0 to x.63.0.

Laptop maker Framework, Python data science platform Anaconda, and form builder tool Tally have all disclosed unauthorised data access due to the vulnerability, which affected the three companies’ cloud-hosted Metabase instances.

Real-time threat and risk intelligence provider Dataminr assessed that in the first week of August just over 4300 hosts reachable over the Internet were running vulnerable versions of Metabase.

It said many of the organisations were in the government, healthcare, energy, finance, telecom, aviation and public sectors.

Savoy said Mathspace has notified schools and individuals affected by the breach, as well as authorities such as the Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, and their counterparts in New Zealand.

Mathspace was founded by Savoy, Mohamad Jebara and Chris Velis in Sydney in 2010, and is used by schools in Australia, New Zealand, the United States, Canada, the United Kingdom, Hong Kong and India.

The current data breach only affected Australian and New Zealand users, however.

Savoy warned Mathspace users to be cautious about messages impersonating the platform, schools and other familiar organisations, using the captured data.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.