CVE-2022-3225: Improper Control of Dynamically-Managed Code Resources in budibase/budibase
Published Sep 16, 2022
·Updated
Improper Access Control in GitHub repository budibase/budibase prior to 1.3.20.
Other sources
Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
— MITRE
Affected Software
4 affected componentsFixes available
npm/@budibase/bbui<1.3.20
1.3.20
npm/@budibase/builder<1.3.20
1.3.20
npm/@budibase/worker<1.3.20
1.3.20
budibase Budibase<1.3.20
Remediation
Event History
Sep 16, 2022
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 17, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-3225?
CVE-2022-3225 has a medium severity due to improper access control vulnerabilities.
2
What versions are affected by CVE-2022-3225?
CVE-2022-3225 affects versions of Budibase prior to 1.3.20.
3
How do I fix CVE-2022-3225?
To fix CVE-2022-3225, upgrade to Budibase version 1.3.20 or later.
4
What is the impact of CVE-2022-3225?
CVE-2022-3225 can allow unauthorized access leading to potential data exposure.
5
Where can I find more information on CVE-2022-3225?
More information on CVE-2022-3225 can be found in the GitHub repository advisory.