logo

Appsmith Patches Full-Read SSRF Vulnerabilities Reported by CloudSEK

ID: 7c612b1a-eaee-581a-96fd-b4d777ee0076

STIX ID: report--7c612b1a-eaee-581a-96fd-b4d777ee0076

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2022-10-04

Date Updated: 2026-04-27

...
...

CloudSEK discovered post-authentication SSRF vulnerabilities in Appsmith’s REST Client (CVE-2022-38298) and Elasticsearch integration (CVE-2022-38299) that allow an attacker to access AWS/GCP metadata endpoints and obtain temporary cloud credentials; researchers demonstrated a blacklist bypass via an external redirect server, reported the issues to Appsmith, and the vendor fixed them in Appsmith version 1.7.12.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.