Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23510

Опубликовано: 09 дек. 2022
Источник: nvd
CVSS3: 9.6
CVSS3: 8.8
EPSS Низкий

Описание

cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cube:cube.js:0.31.23:*:*:*:*:node.js:*:*

EPSS

Процентиль: 60%
0.00404
Низкий

9.6 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.7
github
около 3 лет назад

@cubejs-backend/api-gateway row level security bypass

EPSS

Процентиль: 60%
0.00404
Низкий

9.6 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89