Here's what an email from metabase looks like for those affected:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at https://store.metabase.com.
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [email protected], and we'll get back to you as quickly as we can.
Sameer Al-Sakran
Founder and CEO
Metabase
Based on what they shared in terms of logs and summary, the attacker was scanning tables for valuable data. They took the first N rows from various tables in connected DBs, kind of at random it seems. Possibly some kind of regexing. Here's an example timeline: | Time | Event |
| --- | --- |
| 13:00 | Access gained and authenticated as the administrator account |
| 13:01 – 13:12 | 54 queries were run through that session |
| 13:14 | API key was created (key ID `1`) tied to a service account |
| 13:14 – 13:17 | 19 further queries were run through the API key |
| 13:17 | API key was deleted |