Laptop manufacturer Framework has suffered a data breach following the exploitation of a zero-day vulnerability in Metabase.
The breach involved the loss of contact and delivery data belonging to both private and commercial customers. Framework stated that payment and order information were not compromised during the incident.
Metabase identified an attack on its cloud instances on August 3rd using a previously unknown zero-day vulnerability. The vulnerability is located in the API endpoint used for resetting user passwords.
The Metabase vulnerability is classified as critical.
The vulnerability affects all Metabase versions from 58 to 63, spanning both cloud-based and self-hosted solutions. Following the discovery, Metabase released security advisories and updates.
Metabase stated that cloud customers are already secure, though the company did not specify the number of customers who had experienced data leaks. Framework has informed the relevant supervisory authorities about the attack and hired an IT forensics company to investigate the breach. Additionally, Framework changed the access credentials to its Metabase cloud database.