Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.
{
"cpes": [
"cpe:2.3:a:appsmith:appsmith:1.7.11:*:*:*:*:*:*:*",
"cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*"
],
"severity": "High"
}