Junglewise Threat Intelligence

CVE-2023-50709: Cube API denial of service

CVE-2023-50709 · Severity: low · CVSS 3.1 · Published 2023-12-13

Technologies: @cubejs-backend/api-gateway (npm). Vendors: npm.

Executive brief

Cube is an open-source analytics platform that provides an API gateway for querying data. A flaw in the API gateway allows attackers with basic authentication credentials to crash the entire service by sending a specially crafted request, disrupting availability for all users and causing operational downtime.

Technical details

A denial of service vulnerability (CWE-20: improper input validation) exists in Cube's API gateway endpoint that allows authenticated attackers to crash the service with a malicious request. The vulnerability requires low-privilege authentication (PR:L) and can be triggered over the network without user interaction. A successful exploit causes complete service unavailability affecting all users. The issue has been patched in version 0.34.34 and users are advised to upgrade immediately, with no workarounds available for older versions.

Affected products

  • Cube API Gateway < 0.34.34

Timeline

  • 2023-12-13: disclosed: Vulnerability published; reported by y0d3n in community
  • 2023-12-13: patched: Fix released in v0.34.34

References

Related threats