Server Side Request Forgery Via DNS Rebinding in appsmithorg/appsmith
Reported on
Oct 13th 2022
Description
Appsmith below v1.8.1 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via DNS Rebinding technique to hit AWS internal metadata endpoint and for retrieving data.
Proof of Concept
https://drive.google.com/file/d/1rXnHmhCpo59NjMZJGqKUuOZaQzkXjw6p/view?usp=sharing
Impact
Extract Cloud metadata's like AWS,GCP,Digitalocean etc. and hit internal resources and read access internally hosted web services.
References
This vulnerability is fixed in Appsmith versions greater than v1.8.1
Hi team,
Thanks for assigning cve, Please let me know when it will reflect on cve mitre
Thanks & regards, Basavaraj
Hi team,
Please hide the proof of concept link from the report!
Thanks
And Please add this writeup link in references!
https://basu-banakar.medium.com/ssrf-via-dns-rebinding-cve-2022-4096-b7bf75928bb2
Thanks!