Skip to content
CubeGHSA-9759-3276-g2pm

Cube API denial of service attack

Medium6.5CVE-2023-50709 · Published Dec 13, 2023 · updated Dec 19, 2023

### Impact It is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. ### Patches The issue has been patched in the `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption. ### Workarounds There are currently no workaround for older versions, and the recommendation is to upgrade. ### References The issue was reported by [y0d3n](https://github.com/y0d3n) in our Community Slack and has been promptly patched in the recent update.

GitHub advisory

Affected versions

PackageAffectedFixed in
@cubejs-backend/api-gateway
npm
< 0.34.340.34.34
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
CVE-2023-50709

More Cube advisories

All Cube
Advisory
@cubejs-backend/api-gateway row level security bypass
High7.7Dec 12, 2022
Default Express middleware security check is ignored in production
HighNov 8, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.