CVE-2022-23510

CRITICAL

cube.js 0.31.23 - Authenticated SQL Injection via /v1/sql-runner Endpoint

Title source: llm
STIX 2.1

Description

cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.

Scores

CVSS v3 9.6
EPSS 0.0090
EPSS Percentile 54.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
cube/cube.js 0.31.23
cubejs-backend/api-gateway 0.31.23 - 0.31.24npm
Published Dec 09, 2022
Tracked Since Feb 18, 2026