Junglewise Threat Intelligence

CVE-2022-3225: Budibase improper control of dynamically-managed code resources

CVE-2022-3225 · Severity: low · CVSS 3.1 · Published 2022-09-17

Vendors: Budibase, npm.

Executive brief

Budibase is an open-source low-code platform used to build web applications and databases. A vulnerability in how Budibase handles dynamically-managed code resources could allow authenticated users to inject or manipulate code, potentially leading to unauthorized data modification or application compromise.

Technical details

This vulnerability relates to improper control of dynamically-managed code resources (CWE-284, CWE-913) in Budibase versions prior to 1.3.20. The vulnerability is triggered through an authenticated network vector with low attack complexity and requires user interaction. An authenticated attacker can exploit this to achieve high integrity impact (code injection or manipulation), while confidentiality and availability are not directly affected. The vulnerability was introduced by an encoding fix for issue #7683 related to query string handling, which inadvertently broke or weakened controls on dynamic code execution. A patch is available in version 1.3.20 and later.

Affected products

  • Budibase Budibase prior to 1.3.20

Timeline

  • 2022-09-17: disclosed
  • 2022-09-15: patched: Fix committed; version 1.3.20 released

References

Related threats