Publish GHSA-9759-3276-g2pm

This commit is contained in:
advisory-database[bot]
2023-12-19 20:41:28 +00:00
parent dc4f1c3cb4
commit d7db5fbc99
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9759-3276-g2pm",
"modified": "2023-12-14T21:18:57Z",
"modified": "2023-12-19T20:39:57Z",
"published": "2023-12-13T23:15:56Z",
"aliases": [
"CVE-2023-50709"
],
"summary": "Denial of service attack on the cube-api endpoint",
"summary": "Cube API denial of service attack",
"details": "### Impact\nIt is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.\n\n### Patches\nThe issue has been patched in the `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption.\n\n### Workarounds\nThere are currently no workaround for older versions, and the recommendation is to upgrade.\n\n### References\nThe issue was reported by [y0d3n](https://github.com/y0d3n) in our Community Slack and has been promptly patched in the recent update.",
"severity": [
{