PT-2025-7251 · Hypercube · Hypercube
Published
2025-02-12
·
Updated
2025-02-12
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
hypercube (affected versions not specified)
Description:
The issue allows for remote code execution in web-accessible installations of hypercube. To exploit this, an attacker must make a request against hypercube's endpoints. Standard security practices should be applied.
Recommendations:
For hypercube installations that are directly accessible from the Internet, prevent general access from the Internet to mitigate the risk.
If the microservice is behind a firewall, no patch is necessary, and no further action is required for users who have used official installation methods.
Consider validating the structure of headers passed by the webserver as an additional security measure, but only if the endpoint is publicly exposed.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hypercube