Description
Acunetix determined that it was possible to access Metabase's sensitive files without authentication.
Remediation
Upgrade to the latest version of Metabase
References
Related Vulnerabilities
WordPress Plugin GiveWP-Donation and Fundraising Platform Information Disclosure (2.20.2)
Unrestricted access to NGINX+ API interface (read write)
WordPress Plugin Import all XML, CSV & TXT into WordPress Information Disclosure (3.6.74)
Roundcube Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5382)