CyberRota Analysis
AI-GeneratedBudibase versions prior to 3.41.3 are vulnerable due to inadequate role-based authorization on license management endpoints, enabling authenticated users to delete license keys and manipulate offline tokens. This flaw allows attackers with basic privileges to access critical API endpoints, potentially disabling premium features and downgrading deployments for all users. Organizations using Budibase should prioritize patching to mitigate the risk of unauthorized access and disruption of service.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable premium features and downgrade deployments for all users.