Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-55604


Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of a workspace. Datasources are such a component in a workspace. Yet, in versions of Appsmith prior to 1.51, app viewers are able to get a list of datasources in a workspace they're a member of. This information disclosure does NOT expose sensitive data in the datasources, such as database passwords and API Keys. The attacker needs to have been invited to a workspace as a "viewer", by someone in that workspace with access to invite. The attacker then needs to be able to signup/login to that Appsmith instance. The issue is patched in version 1.51. No known workarounds are available.


Published

2025-03-25T15:15:23.360

Last Modified

2025-10-24T18:11:23.037

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-280

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application appsmith appsmith < 1.51 Yes

References