Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to Server-Side Request Forgery. This can lead to an attacker gaining access to a Budibase AWS secret key. Users of Budibase cloud need to take no action. Self-host users who run Budibase on the public internet and are using a cloud provider that allows HTTP access to metadata information should ensure that when they deploy Budibase live, their internal metadata endpoint is not exposed.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-04-06T16:02:18.684Z

Updated: 2024-08-02T14:00:14.374Z

Reserved: 2023-03-29T17:39:16.143Z

Link: CVE-2023-29010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-06T17:15:10.620

Modified: 2023-04-14T15:56:04.613

Link: CVE-2023-29010

cve-icon Redhat

No data.