CVE-2024-51408: SSRF
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51408?
The severity of CVE-2024-51408 is considered high due to its potential for enabling unauthorized access to AWS metadata credentials.
How do I fix CVE-2024-51408?
To fix CVE-2024-51408, upgrade AppSmith to version 1.46 or later, which addresses the SSRF vulnerability.
What versions are affected by CVE-2024-51408?
CVE-2024-51408 affects AppSmith Community version 1.8.3 through 1.46.
What does SSRF mean in the context of CVE-2024-51408?
In the context of CVE-2024-51408, SSRF stands for Server-Side Request Forgery, which allows an attacker to send requests from the server to an unintended location.
What are the implications of CVE-2024-51408 for AWS services?
The implications of CVE-2024-51408 for AWS services include the potential exposure of sensitive AWS metadata and credentials, leading to further attacks.