From d7db5fbc998b9ce12d374b1a3abca92031a2daf5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 19 Dec 2023 20:41:28 +0000 Subject: [PATCH] Publish GHSA-9759-3276-g2pm --- .../2023/12/GHSA-9759-3276-g2pm/GHSA-9759-3276-g2pm.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-9759-3276-g2pm/GHSA-9759-3276-g2pm.json b/advisories/github-reviewed/2023/12/GHSA-9759-3276-g2pm/GHSA-9759-3276-g2pm.json index b33e3d6b80e..9b117740403 100644 --- a/advisories/github-reviewed/2023/12/GHSA-9759-3276-g2pm/GHSA-9759-3276-g2pm.json +++ b/advisories/github-reviewed/2023/12/GHSA-9759-3276-g2pm/GHSA-9759-3276-g2pm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9759-3276-g2pm", - "modified": "2023-12-14T21:18:57Z", + "modified": "2023-12-19T20:39:57Z", "published": "2023-12-13T23:15:56Z", "aliases": [ "CVE-2023-50709" ], - "summary": "Denial of service attack on the cube-api endpoint", + "summary": "Cube API denial of service attack", "details": "### Impact\nIt is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.\n\n### Patches\nThe issue has been patched in the `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption.\n\n### Workarounds\nThere are currently no workaround for older versions, and the recommendation is to upgrade.\n\n### References\nThe issue was reported by [y0d3n](https://github.com/y0d3n) in our Community Slack and has been promptly patched in the recent update.", "severity": [ {