Skip to content

budibase

v3.40.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai-app-builder ai-applications crud-app crud-application data-application data-apps
+12 more
internal-tools it-workflows low-code low-code-no-code low-code-platform no-code no-code-platform rest-api-framework sql-gui workflow-apps workflow-automation workflow-engine

Affected surfaces

auth deps

Summary

AI summary

[VULN-118] Stop forwarding MongoDB TLS file paths on Cloud and add MSSQL history support.

Full changelog

What's Changed

  • chore(deps): bump js-yaml from 5.2.0 to 5.2.1 in the all-non-major-security group across 1 directory by @dependabot[bot] in https://github.com/Budibase/budibase/pull/19235
  • chore(deps): bump protobufjs from 7.6.4 to 7.6.5 by @dependabot[bot] in https://github.com/Budibase/budibase/pull/19242
  • Support MSSQL history on tables by @adrinr in https://github.com/Budibase/budibase/pull/19222
  • guidelines on choosing a license by @mjashanks in https://github.com/Budibase/budibase/pull/19243
  • Relax Vouch requirements for pull requests by @melohagan in https://github.com/Budibase/budibase/pull/19247
  • feat: nest document list files by @Dakuan in https://github.com/Budibase/budibase/pull/19233
  • [VULN-118] Stop forwarding MongoDB TLS file paths on Cloud by @jvcalderon in https://github.com/Budibase/budibase/pull/19244
  • [GHSA-mqhr-6j6h-74p5] Enforce same-origin check for REST datasource requests by @jvcalderon in https://github.com/Budibase/budibase/pull/19239
  • [VULN-119] Add regression test showing MySQL injection report does not reproduce by @jvcalderon in https://github.com/Budibase/budibase/pull/19250
  • improve workspace home project data resources by @andz-bb in https://github.com/Budibase/budibase/pull/19153

Full Changelog: https://github.com/Budibase/budibase/compare/3.40.0...3.40.1

Security Fixes

  • [VULN-118] Stop forwarding MongoDB TLS file paths on Cloud
  • [GHSA-mqhr-6j6h-74p5] Enforce same-origin check for REST datasource requests

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track budibase

Get notified when new releases ship.

Sign up free

About budibase

AI agents that run your operations. Model agnostic.

All releases →

Related context

Beta — feedback welcome: [email protected]