CVE-2022-38299: Medium severity appsmith vulnerability
Published Sep 12, 2022
·Updated
An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.
Affected Software
1 affected component
AppSmith Appsmith=1.7.11
Remediation
Patch Available
Event History
Sep 12, 2022
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-38299?
CVE-2022-38299 is considered a high severity vulnerability due to its potential exploitation by attackers.
2
How do I fix CVE-2022-38299?
To fix CVE-2022-38299, upgrade Appsmith to version 1.7.12 or later where the vulnerability has been addressed.
3
What software is affected by CVE-2022-38299?
CVE-2022-38299 affects Appsmith version 1.7.11 specifically.
4
What type of vulnerability is CVE-2022-38299?
CVE-2022-38299 is a connection vulnerability that allows unauthorized access to internal metadata endpoints.
5
Can CVE-2022-38299 lead to data exposure?
Yes, CVE-2022-38299 can potentially lead to unauthorized access and data exposure from AWS/GCP internal metadata.