An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Appsmith |
Appsmith |
1.7.11 (including) |
1.7.11 (including) |
References