PT-2026-99358 · Budibase · @Budibase/Server
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase Server versions prior to 3.45.0
Description
The software fails to redact plaintext datasource credentials when broadcasting external table updates to the Builder collaboration websocket room. Users with Builder access can intercept unredacted datasource objects, which may contain sensitive information such as database passwords and API keys, by observing table save or delete operations.
Recommendations
Update Budibase Server to version 3.45.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Budibase/Server