CVE-2024-55965
An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.
- Affected products
- Appsmith
- Appsmith
- < 1.51
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.4% (36th percentile)
- Weakness
- CWE-863
- NVD status
- Analyzed
- Published
- 2025-03-26
CVE-2024-55965 at NVD
1 known exploit for CVE-2024-55965
Proof-of-concept code and exploit modules indexed by Sploitus