PT-2026-99359 · Budibase · Budibase
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase server versions prior to 3.45.0
Description
An information disclosure issue exists where authenticated users can access application metadata and source code belonging to another tenant. By providing a victim tenant's
appId to the 'GET /api/applications/:appId/appPackage' endpoint, an attacker can retrieve sensitive details such as navigation structure, role names, internal screen URLs, JavaScript snippets, and user identifiers due to a lack of authorization checks.Recommendations
Update Budibase server to version 3.45.0 or later.
Restrict access to the 'GET /api/applications/:appId/appPackage' endpoint to minimize the risk of exploitation.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase