3.42.0
4 years ago
1 days ago
Known vulnerabilities in the @budibase/backend-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Information Exposure via the How to fix Information Exposure? Upgrade | <3.40.1 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Improper Authentication in the OIDC SSO authentication process. An attacker can gain unauthorized access to an existing user account, including accounts with administrative privileges, by authenticating through a trusted identity provider that asserts the victim's email address without verifying it. This is only exploitable if the attacker can authenticate through an identity provider trusted by the application and configure it to assert the victim's email with the verification flag set to false. How to fix Improper Authentication? Upgrade | <3.39.30 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the OpenAPI import and REST query execution processes. An attacker can access internal network resources by exploiting DNS rebinding to bypass outbound fetch protections. How to fix Server-side Request Forgery (SSRF)? Upgrade | <3.39.30 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the REST datasource integration due to improper handling of DNS rebinding protections. An attacker can access internal-only services, read sensitive data, or modify and delete internal resources by configuring a REST datasource to use a rebinding hostname that resolves to a safe public IP during validation but to an internal IP at connection time. This allows the attacker to make the server issue arbitrary HTTP requests to internal endpoints, potentially leading to credential theft, data exposure, or service disruption. This is only exploitable if the attacker has an authenticated account with permissions to configure or run a REST datasource. How to fix Server-side Request Forgery (SSRF)? Upgrade | <3.39.30 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the How to fix Cross-site Request Forgery (CSRF)? Upgrade | <3.35.10 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the How to fix Server-side Request Forgery (SSRF)? Upgrade | <3.39.15 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Incorrect Privilege Assignment in the How to fix Incorrect Privilege Assignment? Upgrade | <3.38.2 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the How to fix Server-side Request Forgery (SSRF)? Upgrade | <3.38.1 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the Note: This is only exploitable if plugin loading is enabled and, for full internal network access, if the blacklist is disabled or bypassed. How to fix Server-side Request Forgery (SSRF)? Upgrade | <3.35.10 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Sensitive Cookie Without "HttpOnly" Flag via the How to fix Sensitive Cookie Without "HttpOnly" Flag? Upgrade | <3.35.10 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the authenticated middleware, which uses unanchored regular expressions to match public endpoint patterns against the full request URL, including the query string. An attacker can gain unauthorized access to protected endpoints by appending a public endpoint path as a query parameter, thereby bypassing authentication checks and accessing sensitive user and system information. How to fix Missing Authentication for Critical Function? Upgrade | <3.35.10 |
@budibase/backend-core is a Budibase backend core libraries used in server and worker Affected versions of this package are vulnerable to Insecure Default Initialization of Resource via the How to fix Insecure Default Initialization of Resource? Upgrade | <3.33.4 |