GHSA-9759-3276-g2pm
Dashboard / Vulnerabilities / GHSA-9759-3276-g2pm
Summary: Cube API denial of service attack
Details: ### Impact It is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. ### Patches The issue has been patched in the `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption. ### Workarounds There are currently no workaround for older versions, and the recommendation is to upgrade. ### References The issue was reported by [y0d3n](https://github.com/y0d3n) in our Community Slack and has been promptly patched in the recent update.
References: https://github.com/cube-js/cube/security/advisories/GHSA-9759-3276-g2pm, https://nvd.nist.gov/vuln/detail/CVE-2023-50709, https://github.com/cube-js/cube, https://github.com/cube-js/cube/releases/tag/v0.34.34
Affected packages
Package
Name: @cubejs-backend/api-gateway
Purl: pkg:npm/%40cubejs-backend/api-gateway
Affected ranges
Type: SEMVER
Events:
