Impact
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys.
Affected Systems
The vulnerability affects Budibase deployments prior to version 3.40.0, including all releases of Budibase:Budibase. Any instance running before 3.40.0 that stores datasource credentials in STRING fields is vulnerable.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity. Because exploitation requires only authenticated access with table read permissions, which is commonly granted to users who can view data, the risk of credential exposure is significant. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Nonetheless, the high CVSS and obvious exploitation path make this a priority for patching or mitigation.
OpenCVE Enrichment