PT-2019-20000 · Cube-Js · @Cubejs-Backend/Api-Gateway

Publicado

2019-11-08

·

Atualizado

2019-11-08

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions @cubejs-backend/api-gateway versions prior to 0.11.17
Description The default Express middleware security check is ignored in production, affecting all Cube.js deployments that use affected versions of @cubejs-backend/api-gateway with default Express authentication middleware in the production environment.
Recommendations For versions prior to 0.11.17, update to @cubejs-backend/api-gateway version 0.11.17 to resolve the issue. As a temporary workaround, consider overriding the default authentication Express middleware by using the checkAuthMiddleware option, as described in the documentation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GHSA-4J6X-W426-6RC6

Produtos afetados

@Cubejs-Backend/Api-Gateway