Framework confirms data breach exposed customer addresses and phone numbers

Framework confirms customer data breach through Metabase zero-day

Names, email addresses, phone numbers, login IPs and full addresses were accessed. Framework notified affected customers within hours, but some users argue the company is downplaying the scope of the breach.

© Framework

Framework has confirmed a customer data breach involving Metabase , the business intelligence platform used by the company. Metabase discovered on August 3 that its cloud service had been attacked through a previously unknown vulnerability. Framework was informed on August 6 and subsequently confirmed that the attacker had accessed its Metabase instance. According to the timeline discussed by customers, Framework began notifying affected users within roughly six hours of receiving the warning.

What was obtained

The accessed information included full names, email addresses, login IP addresses, phone numbers and billing and shipping addresses. Country, city, state, ZIP code and company information were also included. Framework for Business customers may additionally have had company phone numbers, VAT numbers, EINs and billing email addresses exposed. Framework says order and payment information was not accessed. The company has rotated credentials for databases connected to Metabase and says it found no unauthorized administrator changes or access to systems outside Metabase.

We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.

— Framework in email to its customers

Highest level exploit

The attack exploited a critical SQL injection vulnerability in Metabase’s /api/session/reset_password endpoint. Metabase says the flaw could be exploited remotely without authentication and could provide administrator access to an affected instance. From there, an attacker could retrieve stored database credentials and read or export information available through connected databases. The vulnerability carries a CVSS score of 10.0, and Metabase has confirmed that it was actively exploited. Metabase Cloud has already been patched, while affected self-hosted versions require an update.

Framework’s response has received mixed feedback from customers. Users on the company’s forum repeatedly praised how quickly Framework confirmed the incident, with one calling the roughly six-hour turnaround uncommon for a breach notification. At the same time, several questioned why Framework titled its email “Notice of Limited Data Breach” when names, addresses, phone numbers and other personally identifiable information had been accessed.

Source: Framework Forums