In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @budibase/backend-core to version 3.35.10 or higher.
@budibase/backend-core is a Budibase backend core libraries used in server and worker
Affected versions of this package are vulnerable to Sensitive Cookie Without "HttpOnly" Flag via the set function in the cookie handling process. An attacker can gain unauthorized access to user accounts and exfiltrate authentication tokens by executing malicious JavaScript in the victim's browser, which can read the session cookie due to missing security flags.