In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @budibase/types to version 3.40.1 or higher.
@budibase/types is a Budibase types
Affected versions of this package are vulnerable to Information Exposure via the rest integration process. An attacker can obtain sensitive authentication credentials by supplying a crafted absolute URL as a query parameter, causing the system to forward stored authorization headers to an attacker-controlled server. This is only exploitable if a REST datasource with stored authentication is used by a query published with the PUBLIC role.