An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-26T00:00:00.000Z
Updated: 2025-03-26T20:09:16.461Z
Reserved: 2024-12-13T00:00:00.000Z
Link: CVE-2024-55963

No data.

Status : Received
Published: 2025-03-26T20:15:21.253
Modified: 2025-03-26T20:15:21.253
Link: CVE-2024-55963

No data.