High severity8.5NVD Advisory· Published Nov 4, 2024· Updated Jun 17, 2026
CVE-2024-51408
CVE-2024-51408
Description
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*range: >=1.8.3,<1.46
- (no CPE)range: <1.46
- AppSmith/Communitydescription
Patches
Vulnerability mechanics
References
3- github.com/jahithoque/Vulnerability-Research/tree/main/CVE-2024-51408nvdExploit
- github.com/appsmithorg/appsmith/pull/29286nvdIssue Tracking
- github.com/appsmithorg/appsmith/releases/tag/v1.46nvdRelease Notes
News mentions
0No linked articles in our index yet.