Skip to content
CubeGHSA-4j6x-w426-6rc6

Default Express middleware security check is ignored in production

HighPublished Nov 8, 2019 · updated Jun 16, 2020

## Default Express middleware security check is ignored in production ### Impact All Cube.js deployments that use affected versions of `@cubejs-backend/api-gateway` with default express authentication middleware in production environment are affected. ### Patches @cubejs-backend/api-gateway@0.11.17 ### Workarounds Override default authentication express middleware: https://cube.dev/docs/@cubejs-backend-server-core#options-reference-check-auth-middleware ### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/cube-js/cube.js/issues * Reach out us in community Slack: https://slack.cube.dev/

GitHub advisory

Affected versions

PackageAffectedFixed in
@cubejs-backend/api-gateway
npm
>= 0.11.0, < 0.11.170.11.17
Details and references

More Cube advisories

All Cube
Advisory
Cube API denial of service attack
Medium6.5Dec 13, 2023
@cubejs-backend/api-gateway row level security bypass
High7.7Dec 12, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.