Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2024-1063
Disclosure Date: January 30, 2024 (last updated February 06, 2024)
Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-27159.
0
Attacker Value
Unknown
CVE-2023-50974
Disclosure Date: January 09, 2024 (last updated January 13, 2024)
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
0
Attacker Value
Unknown
CVE-2023-27159
Disclosure Date: March 31, 2023 (last updated October 08, 2023)
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
0
Attacker Value
Unknown
CVE-2022-2925
Disclosure Date: September 09, 2022 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1.
0
Attacker Value
Unknown
CVE-2021-23682
Disclosure Date: February 16, 2022 (last updated February 23, 2025)
This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.
0