CVE-2024-1063 is a Server-Side Request Forgery (SSRF) vulnerability affecting Appwrite versions up to and including v1.4.13, stemming from an incomplete fix for a prior SSRF issue. This high-severity vulnerability, rated 7.5 CVSS, allows unauthenticated attackers to initiate requests from the server to internal or external resources, potentially leading to information disclosure. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion, organizations using affected Appwrite versions should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.4.13CPE match | cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:* | ||
<= 1.4.13CPE matchmatch criteria | cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.