Threats Tagged 'ghsa-gh4h-34gr-87r7'
View all threats tagged with 'ghsa-gh4h-34gr-87r7'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-gh4h-34gr-87r7'
Click on any threat for detailed analysis and mitigation recommendations
Server: Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders 0 Budibase server versions up to 3.38.1 have a vulnerability where OAuth2 access and refresh tokens of SSO-authenticated users are exposed in automation test results. These tokens are broadcast via WebSocket to all builders connected to the same app and stored in an in-memory cache accessible to any builder polling the test status endpoint. This allows co-builders to steal OAuth2 tokens, enabling unauthorized access to external services. The tokens remain available in memory for about 5 minutes. The issue arises because user context bindings include OAuth2 tokens, which are not sanitized before broadcasting test results. Join the discussion | GCVE Database | 07/24/2026, 21:25:20 UTC Added: 07/25/2026, 23:09:32 UTC |
Showing 1 to 1 of 1 result