Skip to content

Default Express middleware security check is ignored in production

High
paveltiunov published GHSA-4j6x-w426-6rc6 Nov 8, 2019 · 1 comment

Package

npm @cubejs-backend/api-gateway (npm)

Affected versions

0.11.0, 0.11.5, 0.11.6, 0.11.16

Patched versions

0.11.17

Description

Impact

All Cube.js deployments that use affected versions of @cubejs-backend/api-gateway with default express authentication middleware in production environment are affected.

Patches

@cubejs-backend/[email protected]

Workarounds

Override default authentication express middleware: https://cube.dev/docs/@cubejs-backend-server-core#options-reference-check-auth-middleware

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs