PT-2023-22085 · Budibase · Budibase
Votr123
·
Published
2023-04-06
·
Updated
2023-04-14
·
CVE-2023-29010
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 2.4.3
Description
Budibase is a low code platform for creating internal tools, workflows, and admin panels. The issue can lead to an attacker gaining access to a Budibase AWS secret key due to Server-Side Request Forgery. Self-host users who run Budibase on the public internet and are using a cloud provider that allows HTTP access to metadata information should ensure that when they deploy Budibase live, their internal metadata endpoint is not exposed.
Recommendations
For versions prior to 2.4.3, update to version 2.4.3 or later to resolve the issue.
As a temporary workaround, self-host users should ensure their internal metadata endpoint is not exposed when deploying Budibase live.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase