Toutes les vulnérabilités

GHSA-35C4-RVC8-FRHM

npm · @budibase/server

Résumé

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Références