Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c77w-wgvp-cx35

Опубликовано: 26 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
11 месяцев назад

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863