CVE-2024-55964

An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
Configurations

Configuration 1 (hide)

cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-26 20:15

Updated : 2025-04-01 16:34


NVD link : CVE-2024-55964

Mitre link : CVE-2024-55964

CVE.ORG link : CVE-2024-55964


JSON object : View

Products Affected

appsmith

  • appsmith
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')