Impact
Budibase before version 3.40.0 contains server‑side request forgery flaws in the OpenAPI query import and REST query execution features. The flaw lets an authenticated builder‑level user supply DNS names that resolve differently during the initial validation step and during the actual outbound request, effectively bypassing the application’s DNS pinning checks. This DNS rebinding technique can force the server to contact internal HTTP services that would normally be blocked, allowing the attacker to read or manipulate internal resources.
Affected Systems
The vulnerability affects all installations of Budibase distributed as the budibase:server product that run version 3.39.x or earlier. Any instance exposing the OpenAPI import or REST query endpoints to users with builder privileges is susceptible; the flaw specifically targets the Budibase application and its ability to process builder‑level requests.
Risk and Exploitability
The CVSS score of 8.4 classifies this issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of positional information does not diminish the impact of the flaw. Because the exploit requires authenticated builder‑level access, the attack surface is limited to users with that role; however, once accessed, the attacker can reach arbitrary internal hosts, posing a significant confidentiality and integrity risk. Exploitation requires only the ability to trigger the OpenAPI or REST endpoint with a crafted hostname, making it relatively low‑effort for an authorized user who knows the application’s topology.
OpenCVE Enrichment