Critical 9.1 Auth Bypass Hits Budibase Operations Platform
ID: 8c0b8b8c-125d-51df-9b59-259be91932d0
STIX ID: report--8c0b8b8c-125d-51df-9b59-259be91932d0
Feed Name: securityonline.info
Threat Score
Budibase issued a high-priority security update to address a critical CVSS 9.1 authentication bypass where unanchored regex patterns in the authentication middleware allowed attackers to append public endpoint paths in query strings and gain unauthenticated access to protected administrative endpoints; the flaw enables full user enumeration and other administrative actions and is fixed in version 3.35.4 by anchoring regex patterns and switching to ctx.request.path.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
