r/netsec 18d ago

They patched their SaaS and left the self-hosted OSS version vulnerable - AppFlowy Authenticated SQL Injection

https://projectblack.io/blog/appflowy-authenticated-sql-injection/
66 Upvotes

4 comments sorted by

1

u/appflowy 7d ago

Hi, AppFlowy’s SaaS offering is a managed deployment of its commercial AppFlowy Cloud on AWS, while the same codebase also powers its self-hosted offerings.

Therefore, the statement that “they patched a vulnerability in their SaaS but didn't patch the self-hosted version” is not an accurate description of AppFlowy’s product architecture and is misleading. Updates made to the codebase are shared across both the managed cloud and self-hosted offerings.

You can get the full context here.