8.8

CVE-2022-3225

Exploit

Improper Control of Dynamically-Managed Code Resources in budibase/budibase

Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BudibaseBudibase Version < 1.3.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.479
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
security@huntr.dev 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-913 Improper Control of Dynamically-Managed Code Resources

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

https://github.com/budibase/budibase/commit/d35864be0854216693a01307f81ffcabf6d549df
Patch
Third Party Advisory
https://huntr.dev/bounties/a13a56b7-04da-4560-b8ec-0d637d12a245
Patch
Third Party Advisory
Exploit
Issue Tracking