PT-2022-24349 · Appsmith+1 · Appsmith+1

Published

2022-09-12

·

Updated

2024-03-06

·

CVE-2022-38299

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Appsmith version 1.7.11
Description An issue in the Elasticsearch plugin allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.
Recommendations For Appsmith version 1.7.11, consider disabling the Elasticsearch plugin until a patch is available to prevent attackers from connecting disallowed hosts to the AWS/GCP internal metadata endpoint.

Fix

Related Identifiers

BIT-APPSMITH-2022-38299
CVE-2022-38299

Affected Products

Appsmith
Elasticsearch