Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-55965

Опубликовано: 26 мар. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*
Версия до 1.51 (исключая)

EPSS

Процентиль: 40%
0.00184
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
github
11 месяцев назад

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.

EPSS

Процентиль: 40%
0.00184
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863