CyberRota Analysis
AI-GeneratedBudibase versions prior to 3.45.0 are vulnerable due to inadequate validation of per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, enabling users to manipulate role assignments across different workspaces. This flaw allows a builder to elevate their privileges by granting themselves admin roles in other workspaces, potentially compromising sensitive data and operations. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and privilege escalation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.