Impact
The vulnerability is a path traversal flaw that allows an authenticated user to craft S3 object keys containing traversal sequences. The flaw causes files exported from the Budibase workspace to be written to a location outside the intended temporary directory, resulting in the ability to replace or create arbitrary files. The denial of this mechanism leads to potential tampering of system or application files, exposing the system to further compromise. The weakness is classified as CWE-22.
Affected Systems
Budibase server components prior to version 3.40.0 are affected. Users running any earlier Budibase release that accepts S3 object keys as part of the export process are at risk.
Risk and Exploitability
The CVSS score of 9.4 indicates a high severity vulnerability, though the EPSS score is currently not available, the lack of a known exploit does not diminish the risk given the high consequence. The vulnerability can be exploited only by a user with authenticated builder rights, yet those rights are typically granted to trusted users. The absence of a listing in the CISA KEV catalog means there is no evidence of widespread exploitation yet, but the potential impact of arbitrary file write remains significant.
OpenCVE Enrichment