Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fww-hhqw-438g

Опубликовано: 13 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.

Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.

EPSS

Процентиль: 49%
0.00257
Низкий

8.8 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.

EPSS

Процентиль: 49%
0.00257
Низкий

8.8 High

CVSS3

Дефекты

CWE-918