PT-2024-34622 · Appsmith · Appsmith
Jahit Hoque
·
Published
2024-11-04
·
Updated
2024-11-11
·
CVE-2024-51408
CVSS v3.1
8.5
High
| Vector | AC:H/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
AppSmith Community versions 1.8.3 through 1.46
Description
The issue allows for Server-Side Request Forgery (SSRF) via the New DataSource feature for application/json requests to the IP address 169.254.169.254, which is used to retrieve AWS metadata credentials. This can be exploited by attackers to access AWS credentials by manipulating internal server requests.
Recommendations
For versions 1.8.3 through 1.45, update to version 1.46 to resolve the issue.
As a temporary workaround, consider restricting access to the New DataSource feature until the update is applied.
Avoid using the New DataSource feature for application/json requests to the IP address 169.254.169.254 until the issue is resolved.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appsmith