3.38.1
5 years ago
3 months ago
Known vulnerabilities in the @budibase/worker package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@budibase/worker is a Budibase background service Affected versions of this package are vulnerable to Information Exposure in the login lockout process. An attacker can determine whether an email address is registered by sending multiple login attempts and observing differences in the server's response, such as specific headers and messages, which reveal the existence of user accounts. This can be exploited to enumerate valid email addresses and potentially lock out legitimate users by triggering the lockout mechanism. How to fix Information Exposure? A fix was pushed into the | * |
@budibase/worker is a Budibase background service Affected versions of this package are vulnerable to Information Exposure via the How to fix Information Exposure? A fix was pushed into the | * |
@budibase/worker is a Budibase background service Affected versions of this package are vulnerable to Missing Authorization in the How to fix Missing Authorization? A fix was pushed into the | * |
@budibase/worker is a Budibase background service Affected versions of this package are vulnerable to Improper Privilege Management through the Note: This is only exploitable if SMTP email is not configured in the deployment. How to fix Improper Privilege Management? Upgrade | <3.38.1 |