VDB
Sign up
HIGH7.7

GHSA-v226-32c7-x2v7

Cube Core is vulnerable to privilege escalation via a specially crafted request

Quick fix

GHSA-v226-32c7-x2v7 — @cubejs-backend/server-core: upgrade to the fixed version with the command below.

npm install @cubejs-backend/server-core@1.0.14

Details

### **Impact**

It is possible to make a specially crafted request with a valid API token that leads to privilege escalation.

### Affected Versions:

`≥= 0.27.19`

### Mitigation:

Upgrade to a patched version:

- 1.5.13 and later (regular release) - 1.4.2 (active [LTS release](https://cube.dev/docs/product/administration/distribution#long-term-support)) - 1.0.14 (end-of-life LTS release)

### **References**

The issue was reported by our Core engineer, Dmitrii Patsura (@ovr), in our internal Slack and was promptly patched in a recent update.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@cubejs-backend/server-core
Introduced in: 0.27.19Fixed in: 1.0.14
Fixnpm install @cubejs-backend/server-core@1.0.14
npm/@cubejs-backend/server-core
Introduced in: 1.1.0Fixed in: 1.4.2
Fixnpm install @cubejs-backend/server-core@1.4.2
npm/@cubejs-backend/server-core
Introduced in: 1.5.0Fixed in: 1.5.13
Fixnpm install @cubejs-backend/server-core@1.5.13

References