PT-2023-22085 · Budibase · Budibase

Votr123

·

Published

2023-04-06

·

Updated

2023-04-14

·

CVE-2023-29010

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Budibase versions prior to 2.4.3
Description Budibase is a low code platform for creating internal tools, workflows, and admin panels. The issue can lead to an attacker gaining access to a Budibase AWS secret key due to Server-Side Request Forgery. Self-host users who run Budibase on the public internet and are using a cloud provider that allows HTTP access to metadata information should ensure that when they deploy Budibase live, their internal metadata endpoint is not exposed.
Recommendations For versions prior to 2.4.3, update to version 2.4.3 or later to resolve the issue. As a temporary workaround, self-host users should ensure their internal metadata endpoint is not exposed when deploying Budibase live.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2023-29010
GHSA-9XG2-9MCV-985P

Affected Products

Budibase