GHSA-v226-32c7-x2v7
Cube Core is vulnerable to privilege escalation via a specially crafted request
Quick fix
GHSA-v226-32c7-x2v7 — @cubejs-backend/server-core: upgrade to the fixed version with the command below.
npm install @cubejs-backend/server-core@1.0.14Details
### **Impact**
It is possible to make a specially crafted request with a valid API token that leads to privilege escalation.
### Affected Versions:
`≥= 0.27.19`
### Mitigation:
Upgrade to a patched version:
- 1.5.13 and later (regular release) - 1.4.2 (active [LTS release](https://cube.dev/docs/product/administration/distribution#long-term-support)) - 1.0.14 (end-of-life LTS release)
### **References**
The issue was reported by our Core engineer, Dmitrii Patsura (@ovr), in our internal Slack and was promptly patched in a recent update.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.27.19Fixed in: 1.0.14npm install @cubejs-backend/server-core@1.0.141.1.0Fixed in: 1.4.2npm install @cubejs-backend/server-core@1.4.21.5.0Fixed in: 1.5.13npm install @cubejs-backend/server-core@1.5.13