Cyber

Misconfigured Supabase apps expose data in over 16,000 databases

Researchers discovered more than 16,000 misconfigured Supabase databases leaking readable tables with personally identifiable information and passwords.

·1 min read
Misconfigured Supabase apps expose data in over 16,000 databases

Recent security findings have revealed that over 16,000 Supabase databases worldwide have been left exposed due to misconfigurations. These vulnerable databases contain readable tables featuring personally identifiable information (PII), user passwords, and sensitive authentication tokens.

The root cause of these exposures primarily stems from developers overlooking security settings during deployment. Many projects fail to properly restrict public access to database tables, allowing unauthorized entities to easily read and extract sensitive data without requiring credentials.

While Supabase continues to grow in popularity as a flexible backend-as-a-service platform for developers and startups, the ease of implementation sometimes leads to a neglect of foundational security practices, putting vast amounts of user data at risk.

Cybersecurity experts strongly advise all developers and system administrators utilizing Supabase to immediately audit their database access controls and ensure that Row Level Security (RLS) policies are correctly implemented to prevent data leaks.

This widespread security oversight highlights a crucial lesson for tech communities globally: implementing robust security configurations from day one is essential to protecting user privacy and maintaining the integrity of modern cloud-based applications.

#Supabase#Kiberxavfsizlik#Ma'lumotlar bazasi#Dasturlash#API#BleepingComputer

Related articles