GHSA-6jqm-3c9g-pch7
HIGHCVE-2022-23510All authenticated Cube clients could bypass row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint.
- Affected
- = 0.31.23
- Fixed in
- 0.31.24
- Weakness
- CWE-89
- Published
- 2022-12-12
- Source
- github