@cubejs-backend/cubesql is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere
30
Low Risk
Affected versions of this package are vulnerable to Sensitive Information Exposure in Application Logs due to improper handling of security context during error logging. When role-switching operations fail, the system erroneously writes full HTTP authentication context details, including access tokens and base paths, into log files in plain text. Attackers with access to these logs can harvest information to impersonate legitimate users, escalate privileges, bypass authentication controls, or directly access protected resources without authorization.
You are affected if you are using a version that falls within the vulnerable range.
@cubejs-backend/cubesql is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 0.34.11 - 1.3.34.
Upgrade the @cubejs-backend/cubesql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant