Description
Invicti determined that it was possible to access Metabase's sensitive files without authentication.
Remediation
Upgrade to the latest version of Metabase
References
Related Vulnerabilities
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.24)
Roundcube Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5383)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-4042)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3628)
WordPress Plugin WP SlackSync Information Disclosure (1.8.5)