Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses an authentication bypass vulnerability in Budibase, a low-code platform. Attackers could exploit this by registering with a trusted identity provider and asserting a victim's invited email address to claim pending invitations, potentially leading to full tenant compromise, including access to sensitive data and administrative privileges.
- An attacker can bypass login to gain unauthorized access.
- This vulnerability could lead to full system compromise.
- Confirm if your Budibase instance is affected and needs attention.
Attack Path
How an attacker could exploit the issue
An attacker could impersonate an invited user by registering with a trusted identity provider and asserting the victim's email address during the OIDC/SSO login process. This bypasses the need for a valid invite code or verified email, allowing the attacker to claim the pending invitation and gain the privileges associated with it, potentially leading to full tenant compromise.
- Attacker registers with trusted identity provider.
- Bypasses invite code and email verification.
- Full tenant compromise, including admin access.
Live Threat
Current exploitation, exposure, and threat context
An attacker could gain unauthorized access to a Budibase tenant by exploiting an authentication bypass in the OIDC/SSO login. This could occur when a user is invited to a tenant, and the attacker registers with an identity provider (IdP) trusted by the tenant, then asserts the invited user's email address. This allows the attacker to claim the pending invite and gain the privileges of the invited user, potentially leading to full tenant compromise.
- Invited user accounts and tenant access.
- Attacker registers with a trusted IdP.
- Full tenant compromise and access.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Budibase platform, particularly its authentication and SSO features, falls under the purview of the application owners and potentially the platform or infrastructure teams responsible for its deployment. The first actionable step is to identify all Budibase instances, determine their exposure and criticality, and locate the accountable owner before planning remediation.
- Identify Budibase instances and accountable owners.
- Verify SSO and invite functionality exposure.
- Plan remediation considering tenant impact.