AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.
References
Link | Resource |
---|---|
https://github.com/appsmithorg/appsmith/pull/29286 | Issue Tracking |
https://github.com/appsmithorg/appsmith/releases/tag/v1.46 | Release Notes |
https://github.com/jahithoque/Vulnerability-Research/tree/main/CVE-2024-51408 | Exploit |
Configurations
History
No history.
Information
Published : 2024-11-04 14:15
Updated : 2024-11-06 22:06
NVD link : CVE-2024-51408
Mitre link : CVE-2024-51408
CVE.ORG link : CVE-2024-51408
JSON object : View
Products Affected
appsmith
- appsmith
CWE
CWE-918
Server-Side Request Forgery (SSRF)