Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4j6x-w426-6rc6

Опубликовано: 08 нояб. 2019
Источник: github
Github: Прошло ревью

Описание

Default Express middleware security check is ignored in production

Default Express middleware security check is ignored in production

Impact

All Cube.js deployments that use affected versions of @cubejs-backend/api-gateway with default express authentication middleware in production environment are affected.

Patches

@cubejs-backend/api-gateway@0.11.17

Workarounds

Override default authentication express middleware: https://cube.dev/docs/@cubejs-backend-server-core#options-reference-check-auth-middleware

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

@cubejs-backend/api-gateway

npm
Затронутые версииВерсия исправления

>= 0.11.0, <= 0.11.16

0.11.17