@cubejs-backend/api-gateway row level security bypass
Discription

### Impact
All authenticated Cube clients could bypass row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint.

### Patches
The change has been reverted in 0.31.24

### Workarounds
Upgrade to >=0.31.24 or downgrade to Read More

Back to Main

Subscribe for the latest news: