216.73.216.233

CVE-2024-55964

· Published 26/03/2025 20:15 · Modified 27/03/2025 16:45

Labels: CVE-2024-55964 2025-03-26CVE-2024-55964CWE-94[email protected]

Essential information

Published
26/03/2025 20:15
Modified
27/03/2025 16:45
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
appsmith / appsmith cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*
postgresql / postgresql cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

References