Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Denial of service attack on the cube-api endpoint
Vulnerability Description
Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The issue has been patched in `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption. There are currently no workaround for older versions, and the recommendation is to upgrade.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Cube.js 输入验证错误漏洞
Vulnerability Description
Cube.js是美国Cube.js开源的一个开源分析 API 平台。 Cube.js 0.34.34之前版本存在输入验证错误漏洞,该漏洞源于可以通过向Cube API端点提交特制请求来导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A