Sydney’s Mathspace Becomes Target of Delayed Metabase SQL Injection Vulnerability Fixing


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Quick Overview

  • Cyber adversaries took advantage of a severe Metabase flaw to infiltrate Mathspace after the firm neglected to update its self-hosted setup following an advisory issued on August 7.
  • Compromised information comprises user IDs, usernames, first and last names, email addresses, and additional login-related data for students, staff, parents, and guardians.
  • Only users from Australia and New Zealand were impacted, and Mathspace has reached out to authorities including the Office of the Australian Information Commissioner and the Australian Cyber Security Centre.

Exploring the Metabase Flaw

A significant vulnerability in the Metabase business intelligence (BI) tool was taken advantage of by unidentified attackers to breach the online mathematics learning service Mathspace. Despite Metabase issuing a security alert on August 7, prompting users to immediately upgrade their self-hosted versions, Mathspace’s founder and chief technology officer (CTO) Alvin Savoy stated that this action was not carried out.

Postponed Action and Its Ramifications

“Our vulnerability notification process failed to identify and escalate that alert for action,” Savoy mentioned. “We managed to update our instance on August 29 after a later Metabase communication drew our attention.” That lag in deploying patches was sufficient for hackers to access Mathspace’s Metabase instance and extract data. Savoy reported that a variety of data was taken, relating to students, staff, as well as parents and guardians. This encompasses user IDs, usernames, first and last names, email addresses, and other login-related details.

Simple to Exploit Critical SQLi Vulnerability

The Metabase vulnerability carries a peak severity rating of 10.0 out of a potential 10, and it is simple to exploit. It enables structured query language (SQL) command injection via the /api/session/reset_password endpoint, granting a remote attacker administrator-level access to the Metabase instance without any credential input. Various Metabase versions ranging from x.58.0 to x.63.0 are affected by this vulnerability.

Global Repercussions of the Vulnerability

Laptop manufacturer Framework, Python data science platform Anaconda, and form creation tool Tally have all acknowledged unauthorized data access stemming from the vulnerability, affecting the cloud-hosted Metabase instances of these three companies. Real-time threat and risk intelligence provider Dataminr reported that in the first week of August, slightly over 4300 publicly accessible hosts were running vulnerable versions of Metabase. It noted that many of these organizations belonged to the government, healthcare, energy, finance, telecom, aviation, and public sectors.

Mathspace’s Actions and Future Safeguards

Savoy stated that Mathspace has alerted affected schools and individuals, as well as authorities like the Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, and their counterparts in New Zealand. Founded in Sydney in 2010 by Savoy, Mohamad Jebara, and Chris Velis, Mathspace is used by educational institutions in Australia, New Zealand, the United States, Canada, the United Kingdom, Hong Kong, and India. However, this particular data breach solely impacted users from Australia and New Zealand. Savoy cautioned Mathspace users to be vigilant against messages impersonating the platform, schools, and other familiar organizations, utilizing the stolen data.

Conclusion

The infiltration of Mathspace due to a critical Metabase vulnerability highlights the necessity of prompt security updates and effective vulnerability management. This incident underscores the substantial risks related to delayed patching and the extensive consequences such vulnerabilities may have across various sectors.

Reader questions

Frequently asked questions

Fast answers to the questions readers ask most about Sydney's Mathspace Becomes Target of Delayed Metabase SQL Injection Vulnerability Fixing.

What led to the breach at Mathspace?

The breach was instigated by a serious Metabase vulnerability that Mathspace did not address in a timely fashion.

What information was compromised in the breach?

The compromised information consists of user IDs, usernames, first and last names, email addresses, and other login-related details pertaining to students, staff, parents, and guardians.

Who were the users affected by the breach?

The breach affected only users located in Australia and New Zealand.

What actions has Mathspace taken in response to the breach?

Mathspace has informed the affected individuals and relevant authorities. They have also advised users to be watchful of messages that impersonate the platform or associated organizations.

What is the severity rating of the Metabase vulnerability?

The Metabase vulnerability has a highest severity rating of 10.0 out of 10, signifying it is extremely critical and easy to exploit.

How widespread is the impact of the Metabase vulnerability?

The vulnerability has affected a multitude of organizations globally, encompassing those in government, healthcare, energy, finance, telecommunications, aviation, and public sectors.

Posted by Matthew Miller

Matthew Miller is a Brisbane-based Consumer Technology Editor at Techbest covering breaking Australia tech news.

Leave a Reply

Your email address will not be published. Required fields are marked *