GHSA-6x9p-4r67-5gjx: High severity npm/@budibase/server vulnerability
Summary Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.
The affected endpoint is:
POST /api/attachments/:datasourceId/url
The caller can control: text bucket key and receives: text signedUrl publicUrl
This lets a low-privilege published-app user mint S3 PUT URLs using server-side datasource credentials for attacker-chosen object destinations.
Steps:
1. Log in as an admin user. 2. Create a new app/workspace. 3. In the development app context, create an S3 datasource with valid credentials. 4. Publish the app. 5. Create a low-privilege user with the built-in BASIC role on the published production app ID. 6. Log in as that BASIC user. 7. Send: POST /api/attachments/<datasourceId>/url
with: json {"bucket":"foo","key":"bar"} and the published app header: text x-budibase-app-id: <publishedappid> Observe a successful response containing: text signedUrl publicUrl
Observed result
The following behavior:
dev BASIC request: 403 User does not have permission app publish: SUCCESS prod BASIC request: 200 OK Example confirmed runtime values from the final successful run: text prodAppId: appe6b4cdc6cd6949969a83ff11eee88c5a datasourceId: datasource0cec491b26a742468257c62382aa3284 publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar The returned signedUrl contained standard AWS signing markers, including: text X-Amz-Credential=bb X-Amz-Signature X-Amz-Expires=900 Impact
A low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.
Route definition packages/server/src/api/routes/static.ts:45 Authorization logic packages/server/src/middleware/authorized.ts packages/server/src/middleware/resourceId.ts Controller logic packages/server/src/api/controllers/static/index.ts Datasource lookup packages/server/src/sdk/workspace/datasources/datasources.ts
Affected Software
Event History
Frequently Asked Questions
Which users are exposed to this issue?
Low-privilege authenticated users assigned the built-in BASIC role on a published production app are exposed when that app has access to an S3 datasource with valid stored credentials. The observed development-app BASIC request was denied, while the published-app request succeeded.
What does an attacker need to exploit it?
The attacker needs to authenticate as a BASIC user for the published app and send a POST request to /api/attachments/:datasourceId/url with the published app ID in the x-budibase-app-id header. They can supply the bucket and key values used to generate the upload URL.
How can I confirm whether a published app is affected?
Using a BASIC-role account for the published app, request POST /api/attachments/<datasourceId>/url with a bucket and key in the request body and the published app ID header. A successful response containing signedUrl and publicUrl indicates that the account can mint S3 PUT URLs through the datasource credentials.
What access can the resulting URL provide?
The response provides an S3 pre-signed URL for a PUT operation, using the workspace datasource's server-side credentials. The object destination is attacker-controlled through the supplied bucket and key values.