Appsmith

Appsmith

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 24.26%
  • Veröffentlicht 26.03.2025 20:15:21
  • Zuletzt bearbeitet 01.04.2025 16:34:41

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsm...

  • EPSS 44.2%
  • Veröffentlicht 26.03.2025 20:15:21
  • Zuletzt bearbeitet 01.04.2025 16:34:34

An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, cr...

  • EPSS 0.17%
  • Veröffentlicht 26.03.2025 00:00:00
  • Zuletzt bearbeitet 08.07.2025 17:35:30

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure doe...

  • EPSS 0.07%
  • Veröffentlicht 25.03.2025 14:15:05
  • Zuletzt bearbeitet 24.10.2025 18:11:23

Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of a workspace. Datasources are such a component in a workspace. Yet, in versions of Appsmit...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 04.11.2024 14:15:16
  • Zuletzt bearbeitet 06.11.2024 22:06:43

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.

Exploit
  • EPSS 7.27%
  • Veröffentlicht 21.11.2022 15:15:12
  • Zuletzt bearbeitet 21.11.2024 07:34:34

Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.

  • EPSS 0.26%
  • Veröffentlicht 12.09.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:16:12

Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.

  • EPSS 0.17%
  • Veröffentlicht 12.09.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:16:12

An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 05.09.2022 03:15:07
  • Zuletzt bearbeitet 21.11.2024 07:18:20

Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.