This release includes 1 security fix for security teams reviewing exposed deployments.
Published 18d
Developer Productivity
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai-app-builder
ai-applications
crud-app
crud-application
data-application
data-apps
+12 more
internal-tools
it-workflows
low-code
low-code-no-code
low-code-platform
no-code
no-code-platform
rest-api-framework
sql-gui
workflow-apps
workflow-automation
workflow-engine
Affected surfaces
auth
breaking_upgrade
Summary
AI summaryFixed an authorization bypass vulnerability in BuilderSocket SelectApp.
Full changelog
What's Changed
- [Fixed] authorization bypass in BuilderSocket SelectApp by @jvcalderon in https://github.com/Budibase/budibase/pull/19140
- fix: workspace import into existing workspace now restores row data by @Pallavikumarimdb in https://github.com/Budibase/budibase/pull/19128
- fix sub-link nav items disappearing by @ConorWebb96 in https://github.com/Budibase/budibase/pull/19152
- [Automations] Support standard separators in step names by @melohagan in https://github.com/Budibase/budibase/pull/19142
- Default workspace invites to end user by @melohagan in https://github.com/Budibase/budibase/pull/19154
- fix: style account linking page by @Dakuan in https://github.com/Budibase/budibase/pull/19166
- Preserve previously set query column types on preview re-run by @Stropdasman in https://github.com/Budibase/budibase/pull/19084
- Improve UX for Filter component by focusing input and supporting enter key by @Pallavikumarimdb in https://github.com/Budibase/budibase/pull/19170
Full Changelog: https://github.com/Budibase/budibase/compare/3.39.27...3.39.28
Security Fixes
- CVE-2024-12345 — authorization bypass in BuilderSocket SelectApp
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]