CVE-2022-4096: Server-Side Request Forgery (SSRF) in appsmithorg/appsmith
Published Nov 21, 2022
·Updated
Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.
Affected Software
1 affected component
AppSmith Appsmith<1.8.2
Remediation
Event History
Nov 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 28, 58461
Event
06:30 PM
Frequently Asked Questions
1
What is CVE-2022-4096?
CVE-2022-4096 is a Server-Side Request Forgery (SSRF) vulnerability in GitHub repository appsmithorg/appsmith prior to version 1.8.2.
2
How does CVE-2022-4096 affect Appsmith Appsmith?
CVE-2022-4096 affects all versions of Appsmith Appsmith up to and excluding version 1.8.2.
3
What is the severity of CVE-2022-4096?
CVE-2022-4096 has a severity rating of 6.5 (high).
4
What is Server-Side Request Forgery (SSRF)?
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make arbitrary HTTP requests from the vulnerable server.
5
How can I fix CVE-2022-4096?
To fix CVE-2022-4096, upgrade Appsmith Appsmith to version 1.8.2 or later.