GHSA-9759-3276-g2pm
Cube API denial of service attack
Quick fix
GHSA-9759-3276-g2pm — @cubejs-backend/api-gateway: upgrade to the fixed version with the command below.
npm install @cubejs-backend/api-gateway@0.34.34Details
### Impact It is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.
### Patches The issue has been patched in the `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption.
### Workarounds There are currently no workaround for older versions, and the recommendation is to upgrade.
### References The issue was reported by [y0d3n](https://github.com/y0d3n) in our Community Slack and has been promptly patched in the recent update.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.34.34npm install @cubejs-backend/api-gateway@0.34.34