4.9
CVE-2026-73304
- EPSS 0.36%
- Veröffentlicht 13.08.2026 22:05:00
- Zuletzt bearbeitet 14.08.2026 16:17:00
- CVE-Watchlists
- Unerledigt
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the identity-provider credentials of SSO-authenticated users and use the refresh tokens for persistent access to connected services. This issue is fixed in version 3.39.25.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerBudibase
≫
Produkt
budibase
Version
< 3.39.25
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.286 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/Budibase/budibase/releases/tag/3.39.25
https://github.com/Budibase/budibase/security/advisories/GHSA-fcrw-f7gg-6g9f
https://github.com/Budibase/budibase/pull/19110
https://github.com/Budibase/budibase/commit/80a31f6c3354620aa90e50af8a2c614333084621