PT-2026-99352 · Budibase · Budibase
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.45.0
Description
An unauthenticated server-side request forgery (SSRF) and credential exfiltration issue exists in the Microsoft Teams webhook endpoint. The system accepts forged Bot Framework activities containing arbitrary
serviceUrl values. An attacker can send a crafted POST request to inject a controlled serviceUrl that is persisted and used for all subsequent bot replies. This results in the server sending live Microsoft OAuth access tokens within Authorization headers to the attacker's host and allows for blind internal network access.Recommendations
Update Budibase to version 3.45.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase