Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-51408

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.
Attacker Value
Unknown

CVE-2022-4096

Disclosure Date: November 21, 2022 (last updated December 22, 2024)
Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.
Attacker Value
Unknown

CVE-2022-38299

Disclosure Date: September 12, 2022 (last updated October 08, 2023)
An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.
Attacker Value
Unknown

CVE-2022-38298

Disclosure Date: September 12, 2022 (last updated October 08, 2023)
Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.
Attacker Value
Unknown

CVE-2022-39824

Disclosure Date: September 05, 2022 (last updated October 08, 2023)
Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.