Junglewise Threat Intelligence

CVE-2022-23510: Cube.js API Gateway row-level security bypass

CVE-2022-23510 · Severity: low · CVSS 3.1 · Published 2022-12-12

Technologies: @cubejs-backend/api-gateway (npm). Vendors: npm.

Executive brief

Cube.js is a data analytics platform that provides REST APIs for querying databases. A new SQL runner endpoint was introduced that allowed authenticated users to bypass row-level security restrictions and execute arbitrary SQL queries, potentially exposing sensitive data they should not have access to. The vulnerability affected only version 0.31.23 and was immediately patched in 0.31.24.

Technical details

The vulnerability is a security bypass in the /v1/sql-runner endpoint introduced in version 0.31.23. The endpoint was designed to bypass the modeling layer for Cube Cloud functionality but failed to enforce row-level security (RLS) checks that are normally applied through the modeling layer. Any authenticated user with a valid Cube JWT token could submit arbitrary SQL queries via this endpoint, circumventing RLS policies and accessing data they were not authorized to view. The attack requires valid authentication but no user interaction or elevated privileges. The issue was immediately reverted in version 0.31.24, making only version 0.31.23 vulnerable.

Affected products

  • Cube API Gateway 0.31.23

Timeline

  • 2022-12-09: disclosed: CVE published on NVD
  • 2022-12-12: patched: Version 0.31.24 released with complete revert of the vulnerable endpoint

References

Related threats