PT-2023-31615 · Cube · Cube

Y0D3N

·

Published

2023-12-13

·

Updated

2023-12-19

·

CVE-2023-50709

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cube versions prior to 0.34.34
Description The issue allows an attacker to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The problem has been patched in version 0.34.34. It is recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption.
Recommendations For versions prior to 0.34.34, upgrade to version 0.34.34 or later to prevent service disruption. As a temporary workaround is not available for older versions, the recommendation is to upgrade to the latest version.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-50709
GHSA-9759-3276-G2PM

Affected Products

Cube