The Metabase breach resulted in a leak of Framework client data.
Framework has reported a breach of customer personal data following an attack on its supplier, Metabase, which exploited a zero-day vulnerability. The investigation is ongoing, and the exact number of affected individuals has not been specified.
Crius
Framework has notified its clients of a data security breach that resulted in the exposure of personal information. The incident occurred following an attack on the business analytics provider Metabase, where attackers exploited a zero-day vulnerability.
Incident Details
In a letter sent out on August 6, clients were informed about unauthorized access to the following customer data:
- names,
- login IP addresses,
- physical addresses,
- phone numbers,
- email addresses.
Metabase Vulnerability
Metabase announced that its cloud platform, Metabase Cloud, was compromised through a previously unknown vulnerability affecting versions 1.58 and above. Self-hosted Metabase installations were also at risk. It was determined that the attacker used the vulnerability to inject arbitrary SQL queries into the application's database, which could have led to obtaining administrator rights and exposing stored account data.
Framework's Response
After receiving the notification, Framework changed its account credentials and confirmed that there were no changes to administrative access or other systems outside of Metabase. The incident affected all company clients, though the exact number was not specified. An investigation is ongoing to determine whether business-level clients were impacted.
Additional Information
It is known that the Metabase vulnerability has affected at least one other company—Tally.
