Vulnerabilities/

Cube API denial of service attack

Severity:
Medium

Description

It is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.

Recommendation

Update the @cubejs-backend/api-gateway package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@cubejs-backend/api-gateway
Anything's wrong? Let us know Last updated on December 19, 2023

This issue is available in SmartScanner Professional

See Pricing