PT-2019-20000 · Cube-Js · @Cubejs-Backend/Api-Gateway
Publicado
2019-11-08
·
Atualizado
2019-11-08
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions
@cubejs-backend/api-gateway versions prior to 0.11.17
Description
The default Express middleware security check is ignored in production, affecting all Cube.js deployments that use affected versions of @cubejs-backend/api-gateway with default Express authentication middleware in the production environment.
Recommendations
For versions prior to 0.11.17, update to @cubejs-backend/api-gateway version 0.11.17 to resolve the issue.
As a temporary workaround, consider overriding the default authentication Express middleware by using the
checkAuthMiddleware option, as described in the documentation. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
@Cubejs-Backend/Api-Gateway