Vulnerabilities > CVE-2024-51408 - Server-Side Request Forgery (SSRF) vulnerability in Appsmith

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
appsmith
CWE-918

Summary

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.

Vulnerable Configurations

Part Description Count
Application
Appsmith
120

Common Weakness Enumeration (CWE)