Metabase: the data dashboard that was also the keyring
On 3 August, attackers walked into Metabase instances through the "forgot my password" endpoint, unauthenticated, with a CVSS of 10.0. Framework and Tally have already told their users. What an attacker takes from a compromised BI dashboard is not the charts: it is the credentials for every connected database, stored unencrypted unless somebody turned encryption on by hand. Which versions are in range, why this hole never shows up in your CVE feed, and why patching is the easy half of the job.