Over 16,000 Misconfigured Supabase Databases Expose Sensitive Data
A recent discovery by researchers has brought to light a significant security issue involving the popular open-source database platform, Supabase. The issue involves over 16,000 misconfigured databases that unintentionally expose sensitive data to the public.
According to the findings, these exposed databases contain tables with personally identifiable information (PII), passwords, and authentication tokens. The misconfigured Supabase apps are accessible without requiring any authentication or authorization, posing a significant threat to the affected users and their data.
Supabase is an easy-to-use, open-source alternative to solutions like Firebase and MongoDB Atlas. It provides developers with a simple way to set up real-time databases, authentication, and analytics for their projects.
In a statement, a Supabase spokesperson acknowledged the issue and assured users that the team is actively working to resolve the issue. They also advised users to immediately change their database passwords to mitigate potential risks:
"We are aware of the issue involving misconfigured Supabase databases and are actively investigating the situation. We would like to assure our users that we are taking this matter seriously and are committed to resolving the issue promptly. We strongly recommend that users change their database passwords as a precautionary measure to protect their data."
Supabase is urging users to review their database configurations and ensure proper access controls are in place to prevent unauthorized access to their data. The company is currently working on a solution to resolve the misconfigured databases and protect users' sensitive information.
In the meantime, users are advised to exercise caution when interacting with these databases, as unauthorized access could potentially lead to data breaches or other security incidents. It is crucial for users to stay informed and take necessary precautions to safeguard their data.
This issue serves as a reminder of the importance of proper database configuration and security measures. It is essential for developers and users to stay vigilant and ensure their systems are secure to protect sensitive information from unauthorized access.
We will provide updates as they become available regarding Supabase's efforts to resolve the misconfigured databases and the steps users can take to protect themselves.
Source: BleepingComputer
<small>Source: Bleeping Computer — read the original story there.</small>