MEDIUM6.5
GHSA-9vph-2hvm-x66g
Cube Core is vulnerable to Denial of Service (DoS) via crafted request
Quick fix
GHSA-9vph-2hvm-x66g — @cubejs-backend/server-core: upgrade to the fixed version with the command below.
npm install @cubejs-backend/server-core@1.4.2Details
### **Impact**
It is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.
### Affected Versions:
`>= 1.1.17`
### Mitigation:
Upgrade to a patched version:
- 1.5.13 and later (regular release) - 1.4.2 (active [LTS release](https://cube.dev/docs/product/administration/distribution#long-term-support))
### **References**
The issue was reported by our Core engineer, Dmitrii Patsura (@ovr), in our internal Slack and was promptly patched in a recent update.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@cubejs-backend/server-core
Introduced in:
1.1.17Fixed in: 1.4.2Fix
npm install @cubejs-backend/server-core@1.4.2npm/@cubejs-backend/server-core
Introduced in:
1.5.0Fixed in: 1.5.13Fix
npm install @cubejs-backend/server-core@1.5.13