在 Budibase 3.45.0 版本之前,GET /api/chat-links 端点未按工作区(workspace)正确限制作用域,允许构建者(builders)枚举租户内所有工作区的聊天身份链接记录。具有单一工作区构建者访问权限的攻击者可以检索来自其他无权限访问的工作区的敏感聊天身份链接数据,包括用户 ID 和外部聊天服务标识符。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100682 | 8.8 HIGH | Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink |
| CVE-2026-100686 | 8.1 HIGH | Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:g |
| CVE-2026-100684 | 8.1 HIGH | Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC |
| CVE-2026-100680 | 8.1 HIGH | Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import |
| CVE-2026-100683 | 8.0 HIGH | Budibase before 3.45.0 SQL Injection via column-rename DDL |
| CVE-2026-100688 | 6.5 MEDIUM | Budibase server before 3.45.0 Cross-Tenant Information Disclosure |
| CVE-2026-100687 | 5.5 MEDIUM | Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast |
| CVE-2026-100681 | 5.4 MEDIUM | Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook |
No comments yet