Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-29010

Опубликовано: 06 апр. 2023
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to Server-Side Request Forgery. This can lead to an attacker gaining access to a Budibase AWS secret key. Users of Budibase cloud need to take no action. Self-host users who run Budibase on the public internet and are using a cloud provider that allows HTTP access to metadata information should ensure that when they deploy Budibase live, their internal metadata endpoint is not exposed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*
Версия до 2.4.3 (исключая)

EPSS

Процентиль: 43%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918

EPSS

Процентиль: 43%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918