CVE-2023-38646: Metabase < 0.46.6.1 - Remote Code Execution
HoneyLabs honeypots recorded 115 probes matching CVE-2023-38646 from 44 distinct source IP addresses in the last 7 days. Severity is rated critical.
Request paths that identify it
- /api/setup/validate
- /api/session/properties
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 45.156.129.54 | 17 | Sistemas Informaticos, S.A. | Portugal |
| 45.156.128.127 | 13 | Sistemas Informaticos, S.A. | Portugal |
| 45.156.129.131 | 12 | Sistemas Informaticos, S.A. | Portugal |
| 109.105.210.102 | 8 | Zenlayer Inc | Portugal |
| 45.156.128.41 | 7 | Sistemas Informaticos, S.A. | Portugal |
| 109.105.210.104 | 6 | Zenlayer Inc | Portugal |
| 109.105.210.103 | 5 | Zenlayer Inc | Portugal |
| 109.105.210.105 | 4 | Zenlayer Inc | Portugal |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS211680 | Sistemas Informaticos, S.A. | 75 | 26 |
| AS21859 | Zenlayer Inc | 32 | 13 |
| AS51396 | Pfcloud UG (haftungsbeschrankt) | 7 | 4 |
| AS202412 | Omegatech LTD | 1 | 1 |
Captured requests
- /api/session/properties
HTTP client fingerprints (JA4H)
- ge11nn0400_88d30a62b7ad
- ge11nn0500_cac2c496544b
- ge11nn0300_042112399351
CVE report
CVE report
Open a specific CVE from the CVE tracker.