CVE-2022-23510

Published
View on NVD ↗
CVSS v3
9.6
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.

📊 Cube Core is open-source semantic layer for AI, BI and embedded analytics
GitHubGitHub
20.1K