top of page
perceptive_background_267k.jpg

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource c…

Published:

2 april 2026 om 22:00:00

Alert date:

3 april 2026 om 17:05:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector prior to version 3.33.4. The vulnerability occurs because the BLACKLIST_IPS environment variable is not set by default in official deployment configurations, making the SSRF protection mechanism completely ineffective. When the variable is empty, the blacklist function unconditionally returns false, allowing all requests through without restriction. This creates a significant security risk as attackers can potentially access internal resources or perform unauthorized requests. The issue has been patched in version 3.33.4.

Technical details

Mitigation steps:

Affected products:

Budibase

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page