漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Denial of service attack on the cube-api endpoint
Vulnerability Description
Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The issue has been patched in `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption. There are currently no workaround for older versions, and the recommendation is to upgrade.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Cube.js 输入验证错误漏洞
Vulnerability Description
Cube.js是美国Cube.js开源的一个开源分析 API 平台。 Cube.js 0.34.34之前版本存在输入验证错误漏洞,该漏洞源于可以通过向Cube API端点提交特制请求来导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A