An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Appsmith
Appsmith appsmith |
|
CPEs | cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:* | |
Vendors & Products |
Appsmith
Appsmith appsmith |
Thu, 27 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
cvssV3_1
|
Wed, 26 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-26T00:00:00.000Z
Updated: 2025-03-27T13:36:32.205Z
Reserved: 2024-12-13T00:00:00.000Z
Link: CVE-2024-55963

Updated: 2025-03-27T13:35:58.606Z

Status : Analyzed
Published: 2025-03-26T20:15:21.253
Modified: 2025-04-01T16:34:41.947
Link: CVE-2024-55963

No data.