@budibase/worker@3.31.1

Budibase background service

  • latest version

    3.38.1

  • first published

    5 years ago

  • latest version published

    3 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @budibase/worker package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Information Exposure

    @budibase/worker is a Budibase background service

    Affected versions of this package are vulnerable to Information Exposure in the login lockout process. An attacker can determine whether an email address is registered by sending multiple login attempts and observing differences in the server's response, such as specific headers and messages, which reveal the existence of user accounts. This can be exploited to enumerate valid email addresses and potentially lock out legitimate users by triggering the lockout mechanism.

    How to fix Information Exposure?

    A fix was pushed into the master branch but not yet published.

    *
    • H
    Information Exposure

    @budibase/worker is a Budibase background service

    Affected versions of this package are vulnerable to Information Exposure via the tenantUserLookup function. An attacker can obtain sensitive user and tenant information, including email addresses, user IDs, tenant IDs, SSO identifiers, and CouchDB revision tokens, by sending unauthenticated requests to a public API endpoint. The endpoint allows enumeration of users and tenants, enabling targeted attacks against multi-tenant deployments and facilitating further exploitation through user and tenant data harvesting.

    How to fix Information Exposure?

    A fix was pushed into the master branch but not yet published.

    *
    • M
    Missing Authorization

    @budibase/worker is a Budibase background service

    Affected versions of this package are vulnerable to Missing Authorization in the GET /api/global/groups endpoint, which lacks proper role-based access control. An attacker can access sensitive group and role mapping information by sending authenticated requests with BASIC user privileges.

    How to fix Missing Authorization?

    A fix was pushed into the master branch but not yet published.

    *
    • H
    Improper Privilege Management

    @budibase/worker is a Budibase background service

    Affected versions of this package are vulnerable to Improper Privilege Management through the onboardUsers function. An attacker can gain unauthorized administrative privileges by sending crafted requests to the affected endpoint, allowing the creation of accounts with elevated roles and immediate access to generated credentials.

    Note:

    This is only exploitable if SMTP email is not configured in the deployment.

    How to fix Improper Privilege Management?

    Upgrade @budibase/worker to version 3.38.1 or higher.

    <3.38.1