CVE-2026-100680 HIGH
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở
internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys, and database credentials.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 8.1 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| Ngày công bố | 21:16 26/09/2026 |
| Ngày cập nhật | 00:17 29/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [disclosure@vulncheck.com] https://github.com/Budibase/budibase/security/advisories/GHSA-8xr5-pggf-26jq
- [disclosure@vulncheck.com] https://www.vulncheck.com/advisories/budibase-before-3.45.0-arbitrary-local-file-read-via-openapi-import
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/Budibase/budibase/security/advisories/GHSA-8xr5-pggf-26jq
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 00:27 29/09/2026 | MODIFIED | modified_at | 2026-09-28T16:36:05Z | 2026-09-28T17:17:44Z |
| 23:37 28/09/2026 | CREATED | cve | HIGH |