CVE-2022-23510
Dashboard / Vulnerabilities / CVE-2022-23510
Summary: SQl injection in cube-js
Details: cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23510.json, https://github.com/cube-js/cube.js/security/advisories/GHSA-6jqm-3c9g-pch7, https://nvd.nist.gov/vuln/detail/CVE-2022-23510, https://github.com/cube-js/cube.js/commit/3c614674fed6ca17df08bbba8c835ef110167570, https://github.com/cube-js/cube.js/commit/f1140de508e359970ac82b50bae1c4bf152f6041
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
