CVE-2024-55964
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.8epss 6.6%
from disclosure to weapon0 days
Published on NVDMar 26
metasploitMar 25
exploitation probability
6.6%top 7% of all CVEs
observed exploitation
nono source reports it
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a