Vulnerability Description
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Appsmith | Appsmith | >= 1.8.3, < 1.46 |
Related Weaknesses (CWE)
References
- https://github.com/appsmithorg/appsmith/pull/29286Issue Tracking
- https://github.com/appsmithorg/appsmith/releases/tag/v1.46Release Notes
- https://github.com/jahithoque/Vulnerability-Research/tree/main/CVE-2024-51408Exploit
FAQ
What is CVE-2024-51408?
CVE-2024-51408 is a vulnerability with a CVSS score of 8.5 (HIGH). AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.
How severe is CVE-2024-51408?
CVE-2024-51408 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-51408?
Check the references section above for vendor advisories and patch information. Affected products include: Appsmith Appsmith.