CVE-2024-55964: Code Injection
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55964?
CVE-2024-55964 has a high severity rating due to its potential for remote command execution.
How do I fix CVE-2024-55964?
To fix CVE-2024-55964, ensure that your PostgreSQL instance is correctly configured before deploying the Appsmith application.
What causes CVE-2024-55964?
CVE-2024-55964 is caused by an incorrectly configured PostgreSQL instance in the Appsmith image.
Who is affected by CVE-2024-55964?
Users of Appsmith versions prior to 1.52 are affected by CVE-2024-55964.
Can CVE-2024-55964 be exploited remotely?
Yes, CVE-2024-55964 can be exploited remotely if an attacker can access Appsmith and perform specific actions.