在 Budibase 3.45.0 版本之前的服务器中,GET /api/applications/:appId/appPackage 端点存在一个跨租户信息泄露漏洞,允许已认证用户读取其他租户的应用元数据和源代码。攻击者可以提交受害租户的应用 ID,以获取敏感的应用详情,包括导航结构、角色名称、内部屏幕 URL、JavaScript 代码片段以及用户标识符,而无需通过任何授权检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100682 | 8.8 HIGH | Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink |
| CVE-2026-100686 | 8.1 HIGH | Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:g |
| CVE-2026-100684 | 8.1 HIGH | Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC |
| CVE-2026-100680 | 8.1 HIGH | Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import |
| CVE-2026-100683 | 8.0 HIGH | Budibase before 3.45.0 SQL Injection via column-rename DDL |
| CVE-2026-100685 | 7.7 HIGH | Budibase before 3.45.0 Information Disclosure via Chat Links |
| CVE-2026-100687 | 5.5 MEDIUM | Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast |
| CVE-2026-100681 | 5.4 MEDIUM | Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook |
No comments yet