CVE-2024-55964

An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
Configurations

Configuration 1 (hide)

cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*

History

01 Apr 2025, 16:34

Type Values Removed Values Added
CPE cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*
References () https://github.com/appsmithorg/appsmith/security/advisories/GHSA-m95x-4w54-gc83 - () https://github.com/appsmithorg/appsmith/security/advisories/GHSA-m95x-4w54-gc83 - Vendor Advisory
First Time Appsmith appsmith
Appsmith

27 Mar 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Se detectó un problema en Appsmith antes de la versión 1.52. Una instancia de PostgreSQL configurada incorrectamente en la imagen de Appsmith provoca la ejecución remota de comandos dentro del contenedor Docker de Appsmith. El atacante debe poder acceder a Appsmith, iniciar sesión, crear una fuente de datos, crear una consulta en dicha fuente y ejecutarla.
CWE CWE-94

26 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-26 20:15

Updated : 2025-04-01 16:34


NVD link : CVE-2024-55964

Mitre link : CVE-2024-55964

CVE.ORG link : CVE-2024-55964


JSON object : View

Products Affected

appsmith

  • appsmith
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')