OSV 1.4.0 · unreviewed · 修改于 2026-08-28 20:30
发布时间
2026-08-28 20:30
GitHub 审查时间
—
NVD 发布时间
2026-08-28 20:16
源文件
advisories/unreviewed/2026/08/GHSA-7q8g-4mpg-9gfm/GHSA-7q8g-4mpg-9gfm.json
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
该公告没有提供结构化的受影响软件包信息。