Framework公司因Metabase存在的0-day漏洞而发生数据泄露事件[1]。泄露数据包含客户个人身份信息,但不涉及支付或账单信息[1]。
Metabase在发现该事件后用时3天才通知商业合作伙伴[1]。Framework在收到Metabase通知后仅用6小时完成内部确认并通知客户[1]。社区用户对Framework的通知响应速度表示赞赏[1],但有人对数据与第三方共享以及官方使用"有限泄露"一词的措辞提出了保留意见[1]。
Framework表示将评估与商业智能平台共享数据的范围和深度,并限制其访问权限[1]。
Framework has disclosed a data breach resulting from a zero-day vulnerability in Metabase, a business intelligence platform the company uses internally.[1] The breach exposed customer personal identity information, though payment and billing data were not compromised.[1]
The incident demonstrates Framework's rapid response to the security event.[1] After Metabase notified the company of the vulnerability, Framework confirmed the breach internally and alerted its customers within just six hours.[1] Metabase itself took three days from discovering the incident to notifying its commercial partners.[1]
In response to the breach, Framework plans to reassess the scope and depth of data shared with business intelligence platforms and restrict access accordingly.[1] While community members have praised Framework's notification speed, some have expressed reservations about data sharing practices with third parties and the company's use of the term "limited breach."[1]