CVE-2023-50709

MEDIUM

cube.js < 0.34.34 - Denial of Service via Crafted API Request

Title source: llm
STIX 2.1

Description

Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The issue has been patched in `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption. There are currently no workaround for older versions, and the recommendation is to upgrade.

References (2)

Core 2
Core References

Scores

CVSS v3 6.5
EPSS 0.0072
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
cube/cube.js < 0.34.34
cubejs-backend/api-gateway 0 - 0.34.34npm
Published Dec 13, 2023
Tracked Since Feb 18, 2026