CyberRota Analysis
AI-GeneratedBudibase versions prior to 3.45.0 are vulnerable due to improper scoping of the GET /api/chat-links endpoint, which allows attackers with builder access in one workspace to enumerate sensitive chat identity link records across all workspaces within a tenant. This could lead to unauthorized access to user IDs and external chat service identifiers, posing a significant risk to user privacy and data security. Organizations using Budibase should prioritize patching this vulnerability to prevent potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to access.