High severity8.8NVD Advisory· Published Sep 16, 2022· Updated Jun 17, 2026
CVE-2022-3225
CVE-2022-3225
Description
Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@budibase/workernpm | < 1.3.20 | 1.3.20 |
@budibase/buildernpm | < 1.3.20 | 1.3.20 |
@budibase/bbuinpm | < 1.3.20 | 1.3.20 |
Affected products
5- ghsa-coords3 versions
< 1.3.20+ 2 more
- (no CPE)range: < 1.3.20
- (no CPE)range: < 1.3.20
- (no CPE)range: < 1.3.20
Patches
Vulnerability mechanics
References
5- github.com/budibase/budibase/commit/d35864be0854216693a01307f81ffcabf6d549dfnvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/a13a56b7-04da-4560-b8ec-0d637d12a245nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-x92g-49gh-63qmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-3225ghsaADVISORY
- github.com/Budibase/budibase/releases/tag/v1.3.20ghsaWEB
News mentions
0No linked articles in our index yet.