This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 4d
Developer Productivity
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
ai-app-builder
ai-applications
crud-app
crud-application
data-application
data-apps
+12 more
internal-tools
it-workflows
low-code
low-code-no-code
low-code-platform
no-code
no-code-platform
rest-api-framework
sql-gui
workflow-apps
workflow-automation
workflow-engine
Affected surfaces
auth
deps
Summary
AI summary[VULN-118] Stop forwarding MongoDB TLS file paths on Cloud and add MSSQL history support.
Full changelog
What's Changed
- chore(deps): bump js-yaml from 5.2.0 to 5.2.1 in the all-non-major-security group across 1 directory by @dependabot[bot] in https://github.com/Budibase/budibase/pull/19235
- chore(deps): bump protobufjs from 7.6.4 to 7.6.5 by @dependabot[bot] in https://github.com/Budibase/budibase/pull/19242
- Support MSSQL history on tables by @adrinr in https://github.com/Budibase/budibase/pull/19222
- guidelines on choosing a license by @mjashanks in https://github.com/Budibase/budibase/pull/19243
- Relax Vouch requirements for pull requests by @melohagan in https://github.com/Budibase/budibase/pull/19247
- feat: nest document list files by @Dakuan in https://github.com/Budibase/budibase/pull/19233
- [VULN-118] Stop forwarding MongoDB TLS file paths on Cloud by @jvcalderon in https://github.com/Budibase/budibase/pull/19244
- [GHSA-mqhr-6j6h-74p5] Enforce same-origin check for REST datasource requests by @jvcalderon in https://github.com/Budibase/budibase/pull/19239
- [VULN-119] Add regression test showing MySQL injection report does not reproduce by @jvcalderon in https://github.com/Budibase/budibase/pull/19250
- improve workspace home project data resources by @andz-bb in https://github.com/Budibase/budibase/pull/19153
Full Changelog: https://github.com/Budibase/budibase/compare/3.40.0...3.40.1
Security Fixes
- [VULN-118] Stop forwarding MongoDB TLS file paths on Cloud
- [GHSA-mqhr-6j6h-74p5] Enforce same-origin check for REST datasource requests
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]