VDB
Sign up
MEDIUM6.5

GHSA-9vph-2hvm-x66g

Cube Core is vulnerable to Denial of Service (DoS) via crafted request

Quick fix

GHSA-9vph-2hvm-x66g — @cubejs-backend/server-core: upgrade to the fixed version with the command below.

npm install @cubejs-backend/server-core@1.4.2

Details

### **Impact**

It is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.

### Affected Versions:

`>= 1.1.17`

### Mitigation:

Upgrade to a patched version:

- 1.5.13 and later (regular release) - 1.4.2 (active [LTS release](https://cube.dev/docs/product/administration/distribution#long-term-support))

### **References**

The issue was reported by our Core engineer, Dmitrii Patsura (@ovr), in our internal Slack and was promptly patched in a recent update.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@cubejs-backend/server-core
Introduced in: 1.1.17Fixed in: 1.4.2
Fixnpm install @cubejs-backend/server-core@1.4.2
npm/@cubejs-backend/server-core
Introduced in: 1.5.0Fixed in: 1.5.13
Fixnpm install @cubejs-backend/server-core@1.5.13

References