PT-2023-31615 · Cube · Cube
Y0D3N
·
Published
2023-12-13
·
Updated
2023-12-19
·
CVE-2023-50709
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cube versions prior to 0.34.34
Description
The issue allows an attacker to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The problem has been patched in version 0.34.34. It is recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption.
Recommendations
For versions prior to 0.34.34, upgrade to version 0.34.34 or later to prevent service disruption.
As a temporary workaround is not available for older versions, the recommendation is to upgrade to the latest version.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cube