Default Express middleware security check is ignored in production
Package
Affected versions
>= 0.11.0, <= 0.11.16
Patched versions
0.11.17
Description
Published to the GitHub Advisory Database
Nov 8, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Default Express middleware security check is ignored in production
Impact
All Cube.js deployments that use affected versions of
@cubejs-backend/api-gateway
with default express authentication middleware in production environment are affected.Patches
@cubejs-backend/api-gateway@0.11.17
Workarounds
Override default authentication express middleware: https://cube.dev/docs/@cubejs-backend-server-core#options-reference-check-auth-middleware
For more information
If you have any questions or comments about this advisory:
References