CyberRota Analysis
AI-GeneratedBudibase versions prior to 3.41.3 are vulnerable due to inadequate validation of app-scoped builder role assignments, enabling authenticated users to exploit the public user create and update endpoints. This flaw allows attackers to escalate privileges by manipulating the user update API, potentially granting them unauthorized builder access to other applications within the same tenant. Organizations using Budibase should prioritize patching to mitigate the risk of privilege escalation and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.