Résumé
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
Détails de l’avis
Summary
Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.
The affected endpoint is:
POST /api/attachments/:datasourceId/url
The caller can control:
bucket
key
and receives:
signedUrl
publicUrl
This lets a low-privilege published-app user mint S3 PUT URLs using server-side datasource credentials for attacker-chosen object destinations.
Steps:
- Log in as an admin user.
- Create a new app/workspace.
- In the development app context, create an S3 datasource with valid credentials.
- Publish the app.
- Create a low-privilege user with the built-in BASIC role on the published production app ID.
- Log in as that BASIC user.
- Send:
POST /api/attachments/<datasourceId>/url
with:
{"bucket":"foo","key":"bar"}
and the published app header:
x-budibase-app-id: <published_app_id>
Observe a successful response containing:
signedUrl
publicUrl
Observed result
The following behavior:
dev BASIC request: 403 User does not have permission app publish: SUCCESS prod BASIC request: 200 OK Example confirmed runtime values from the final successful run:
prodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a
datasourceId: datasource_0cec491b26a742468257c62382aa3284
publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar
The returned signedUrl contained standard AWS signing markers, including:
X-Amz-Credential=bb
X-Amz-Signature
X-Amz-Expires=900
Impact
A low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.
Route definition
packages/server/src/api/routes/static.ts:45
Authorization logic
packages/server/src/middleware/authorized.ts
packages/server/src/middleware/resourceId.ts
Controller logic
packages/server/src/api/controllers/static/index.ts
Datasource lookup
packages/server/src/sdk/workspace/datasources/datasources.ts
Références
Vulnérabilités liées
Tout Supply chain →- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- HIGHCVE-2026-72795
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
- MEDIUMCVE-2026-72796
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
- MEDIUMCVE-2026-72797
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
- HIGHCVE-2026-72798
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
- MEDIUMCVE-2026-72799
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers