Budibase

Budibase

66 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 17.08.2026 20:32:05
  • Zuletzt bearbeitet 18.08.2026 14:17:11

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with...

  • EPSS 0.47%
  • Veröffentlicht 17.08.2026 20:28:40
  • Zuletzt bearbeitet 18.08.2026 13:17:22

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/serve...

  • EPSS 0.17%
  • Veröffentlicht 17.08.2026 20:27:24
  • Zuletzt bearbeitet 17.08.2026 22:17:26

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/utils/fetch.ts...

  • EPSS 0.24%
  • Veröffentlicht 17.08.2026 20:24:59
  • Zuletzt bearbeitet 18.08.2026 16:18:12

Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statement without e...

  • EPSS 0.37%
  • Veröffentlicht 13.08.2026 22:05:02
  • Zuletzt bearbeitet 18.08.2026 02:17:28

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 22:05:00
  • Zuletzt bearbeitet 14.08.2026 16:17:00

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshTo...

  • EPSS 0.33%
  • Veröffentlicht 13.08.2026 22:04:53
  • Zuletzt bearbeitet 14.08.2026 18:19:09

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backti...

  • EPSS 0.31%
  • Veröffentlicht 13.08.2026 22:04:50
  • Zuletzt bearbeitet 14.08.2026 17:20:32

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and packages/backend-core/src/midd...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 21:54:45
  • Zuletzt bearbeitet 14.08.2026 17:20:31

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve da...

  • EPSS 0.33%
  • Veröffentlicht 13.08.2026 21:54:45
  • Zuletzt bearbeitet 17.08.2026 16:17:45

Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted midd...