Описание
cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cube:cube.js:0.31.23:*:*:*:*:node.js:*:*
EPSS
Процентиль: 60%
0.00404
Низкий
9.6 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 7.7
github
около 3 лет назад
@cubejs-backend/api-gateway row level security bypass
EPSS
Процентиль: 60%
0.00404
Низкий
9.6 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-89