Impact
The vulnerability allows an attacker to supply an arbitrary URL in the query import endpoint, causing the server to fetch and return data from that location without validation. This can expose internal network services, including cloud metadata endpoints, to unauthenticated access and confidentiality or integrity compromise.
Affected Systems
Budibase Server versions prior to 3.41.3 are affected. The query import endpoint does not verify user-supplied URLs, permitting SSRF against internal and restricted resources.
Risk and Exploitability
The CVSS score is 7.1, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw via the exposed endpoint, potentially retrieving data from internal services, and therefore the risk is significant unless mitigated.
OpenCVE Enrichment