Appsmith Patches Full-Read SSRF Vulnerabilities Reported by CloudSEK
ID: 7c612b1a-eaee-581a-96fd-b4d777ee0076
STIX ID: report--7c612b1a-eaee-581a-96fd-b4d777ee0076
Feed Name: CloudSEK Blog
Threat Score
CloudSEK discovered post-authentication SSRF vulnerabilities in Appsmith’s REST Client (CVE-2022-38298) and Elasticsearch integration (CVE-2022-38299) that allow an attacker to access AWS/GCP metadata endpoints and obtain temporary cloud credentials; researchers demonstrated a blacklist bypass via an external redirect server, reported the issues to Appsmith, and the vendor fixed them in Appsmith version 1.7.12.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
