Impact
The vulnerability is a server‑side request forgery in Budibase’s REST datasource integration that does not validate HTTP redirect targets against the IP blacklist. An attacker who has Builder privileges can point a datasource to an external server that issues a redirect to an internal IP address, thus bypassing blacklist filtering and allowing the app to interrogate internal services or cloud metadata endpoints. This undermines the confidentiality and integrity of internal resources and can serve as a foothold for further exploitation.
Affected Systems
Budibase versions prior to 3.38.1 are affected. Users running Budibase 3.37.x, 3.38.0, or earlier should be aware that the SSRF protection is incomplete and internal IP addresses can be reached through crafted redirects.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. No EPSS data is available, so exploitation likelihood cannot be quantified, but the feature is exposed to users with Builder role, a common internal role, making the vulnerability potentially exploitable by insiders or compromised accounts. The vulnerability is not listed in the CISA KEV catalog, and official advisories recommend patching as the primary mitigation. The attack path requires the ability to configure a REST datasource and an external server that issues a redirect, so network and role boundaries influence practical exploitability.
OpenCVE Enrichment