An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:appsmith:appsmith:1.7.11:*:*:*:*:*:*:*",
"cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*"
]
}