An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Appsmith | Appsmith | 1.7.11 (including) | 1.7.11 (including) |
References