CVE-2022-23510

Source
https://cve.org/CVERecord?id=CVE-2022-23510
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23510.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23510
Aliases
Published
2022-12-09T22:12:10.191Z
Modified
2026-08-12T03:51:22.473527440Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
SQl injection in cube-js
Details

cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23510.json",
    "cwe_ids": [
        "CWE-89"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/cube-js/cube

Affected ranges

Type
GIT
Repo
https://github.com/cube-js/cube
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:cube:cube.js:0.31.23:*:*:*:*:node.js:*:*",
    "extracted_events": [
        {
            "introduced": "0.31.23"
        },
        {
            "last_affected": "0.31.23"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.31.23
= 0.*
= 0.31.23
v0.*
v0.31.23

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23510.json"