Skip to content

baserow

v2.3.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 5d Relational Databases
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

airtable airtable-alternative airtable-replacement application-builder automations dashboards
+10 more
database low-code no-code no-code-database no-code-platform online-database postgresql restful-api self-hosted spreadsheet

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Updates Bug fixes, New features, and Refactors across a mixed release.

Full changelog

New features

  • [Database] Show anonymous public view visitors in editor's presence bar #5702
  • [Database] Add links and rich formatting to form and field descriptions #1851
  • [Database] Data syncs that fetch from a user configured URL (such as a self-hosted GitLab or Jira instance, or an iCal feed) can now be blocked from reaching private network addresses by setting the BASEROW_DATA_SYNC_ALLOW_PRIVATE_ADDRESS env var to false.
  • [Core] Monitor celery beat periodic tasks with Sentry cron monitors when Sentry is enabled
  • [Core] OAuth2 and OpenID Connect SSO providers with admin configurable URLs can now be blocked from reaching private network addresses by setting the BASEROW_SSO_ALLOW_PRIVATE_ADDRESS env var to false.

Bug fixes

  • [Database] Fix link row field modal unselecting newly created rows due to a race condition with real-time updates #5735
  • [Builder] Fixed workflow actions inside collection elements failing to resolve the current_record.
  • [Core] Prevent impersonating deactivated users via the admin impersonate endpoint
  • [Automation] Prevents the webhook address of an HTTP trigger from being changed after it is created
  • [Core] Reduce backend memory usage by releasing each API response's memory right after it is sent
  • [Database] Show an error on AI fields with a broken prompt and block generating until fixed #3088
  • [Core] Workspace import now strictly validates the manifest schema version, and an unsupported version returns a clear invalid file error.

Refactors

  • [Core] Simplify 2FA verify endpoint to resolve user identity from the authentication token instead of the request body. #5743
  • [Builder] Updated 'formula' references in builder, automation & integrations module so that they now refer to 'expressions'.

Security Fixes

  • Prevent impersonating deactivated users via the admin impersonate endpoint

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track baserow

Get notified when new releases ship.

Sign up free

About baserow

Build databases, automations, apps & agents with AI — no code. Open source platform available on cloud and self-hosted. GDPR, HIPAA, SOC 2 compliant. Best Airtable alternative.

All releases →

Related context

Beta — feedback welcome: [email protected]