PT-2022-16041 · Cube-Js · Cube-Js

Published

2022-12-09

·

Updated

2022-12-13

·

CVE-2022-23510

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions cube-js version 0.31.23
Description The issue concerns a headless business intelligence platform where all authenticated clients could bypass SQL row-level security and run arbitrary SQL via the /v1/sql-runner endpoint. This was resolved in version 0.31.24.
Recommendations For version 0.31.23, upgrade to version 0.31.24 or downgrade to version 0.31.22 to resolve the issue. As a temporary workaround, consider restricting access to the /v1/sql-runner endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-23510
GHSA-6JQM-3C9G-PCH7

Affected Products

Cube-Js