Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to Server-Side Request Forgery. This can lead to an attacker gaining access to a Budibase AWS secret key. Users of Budibase cloud need to take no action. Self-host users who run Budibase on the public internet and are using a cloud provider that allows HTTP access to metadata information should ensure that when they deploy Budibase live, their internal metadata endpoint is not exposed.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-04-06T16:02:18.684Z

Updated: 2023-04-06T16:02:18.684Z

Reserved: 2023-03-29T17:39:16.143Z


Link: CVE-2023-29010

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-04-06T17:15:10.620

Modified: 2023-04-14T15:56:04.613


Link: CVE-2023-29010

JSON object: View

cve-icon Redhat Information

No data.

CWE