CVE-2024-55963 describes an improper access control vulnerability in Appsmith versions prior to 1.51, allowing non-admin users to trigger a server restart and cause a denial of service. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and can lead to continuous service disruption within the Appsmith container. While there is no known active exploitation or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness. Although an ExploitDB entry for Appsmith 1.47 mentions RCE, this specific CVE is limited to denial of service.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.51CPE matchmatch criteria | cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.