Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to Server-Side Request Forgery. This can lead to an attacker gaining access to a Budibase AWS secret key. Users of Budibase cloud need to take no action. Self-host users who run Budibase on the public internet and are using a cloud provider that allows HTTP access to metadata information should ensure that when they deploy Budibase live, their internal metadata endpoint is not exposed.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-04-06T16:02:18.684Z
Updated: 2024-08-02T14:00:14.374Z
Reserved: 2023-03-29T17:39:16.143Z
Link: CVE-2023-29010
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2023-04-06T17:15:10.620
Modified: 2023-04-14T15:56:04.613
Link: CVE-2023-29010
Redhat
No data.