CVE-2024-55963
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.
- Affected products
- Appsmith
- Appsmith
- < 1.51
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 27.7% (98th percentile)
- Weakness
- CWE-284
- NVD status
- Analyzed
- Published
- 2025-03-26
CVE-2024-55963 at NVD
6 known exploits for CVE-2024-55963
Proof-of-concept code and exploit modules indexed by Sploitus