Metabase
Discovery
# Default port
# 3000 - HTTP
# Nmap fingerprint
nmap -sC -sV TARGET -p 3000
# Sign in to Metabase
# Version check - look in page source or API
curl http://TARGET:3000/api/session/properties | jq '.version'CVE-2023-38646 - Pre-Auth RCE via Setup Token
Get Setup Token
Exploitation
Reverse Shell
Post-Exploitation
Metabase Database
Extracting Credentials from H2 Database
Cracking Metabase Password Hashes
Docker Environment Variables
Container Escape
Useful API Endpoints
Endpoint
Description
Default Credentials
References
Last updated