CVE-2023-50709
Last modified
CVE-2023-50709 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The issue has been patched in `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption. There are currently no workaround for older versions, and the recommendation is to upgrade.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cube | Cube.Js | < 0.34.34 |
References
- https://github.com/cube-js/cube/security/advisories/GHSA-9759-3276-g2pmThird Party Advisory
- https://github.com/cube-js/cube/security/advisories/GHSA-9759-3276-g2pmThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-50709?
How severe is CVE-2023-50709?
How do I fix CVE-2023-50709?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-50703 An attacker with network access could perform a man-in-the-…5.9
- CVE-2023-50704 An attacker could construct a URL within the applicatio…6.1
- CVE-2023-50705 An attacker could create malicious requests to obta…5.3
- CVE-2023-50706 A user without administrator permissions with a…4.3
- CVE-2023-50707 Through the exploitation of active user sessions, an attack…7.5
- CVE-2023-50708yii2-authclient is an extension that adds OpenID, OAuth, OAu…9.8
- CVE-2023-5071The Sitekit plugin for WordPress is vulnerable to Stored Cro…5.4
- CVE-2023-50710Hono is a web framework written in TypeScript. Prior to vers…4.3
- CVE-2023-50711vmm-sys-util is a collection of modules that provides helper…9.8
- CVE-2023-50712Iris is a web collaborative platform aiming to help incident…5.4
- CVE-2023-50713Speckle Server provides server, frontend, 3D viewer, and oth…5
- CVE-2023-50714yii2-authclient is an extension that adds OpenID, OAuth, OAu…8.8
Are you affected by CVE-2023-50709?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
