CVE-2024-55964·Docker vulnerability
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
- Severity
- critical
- Software
- Docker
- Fixed in
- 1.52
- Published
- 2025-03-26
Affected versions
Until: 1.52
Fixed in: 1.52
How to fix this CVE
Upgrade Appsmith to version 1.52 or later to remediate a critical PostgreSQL misconfiguration flaw within Docker containers. This vulnerability allows authenticated users to execute arbitrary commands on the host system through crafted database queries. Organizations running older Appsmith versions should prioritize this update as part of their container security hardening process.
sudo dnf update docker-ceDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement network segmentation to restrict direct access to Appsmith instances from untrusted networks. Deploy a WAF rule to rate-limit datasource creation and query execution endpoints (POST /api/v1/datasources, POST /api/v1/queries), and require multi-factor authentication for all Appsmith user accounts to prevent unauthorized database query execution.How to check if you are affected
- Step 1: Check the Appsmith version by running `docker exec <container_id> cat /opt/appsmith/package.json | grep version` or checking the UI footer for the version number
- Step 2: Identify exposed Appsmith instances by scanning network access logs for connections to port 80/443 and verify authentication requirements are enforced
- Step 3: Review PostgreSQL query logs within the Appsmith container for suspicious SQL commands containing shell metacharacters (backticks, pipes, semicolons) or system command patterns using `docker logs <container_id> | grep -i 'execute\|shell\|command'`
- Step 4: Verify successful remediation by confirming Appsmith version >= 1.52 via the admin dashboard or by inspecting the running container's version metadata
FAQ
What is CVE-2024-55964?
CVE-2024-55964 is a critical remote code execution vulnerability in Appsmith versions prior to 1.52, where misconfigurations in the bundled PostgreSQL database allow authenticated users to execute arbitrary system commands through crafted SQL queries executed within the Docker container.
Is CVE-2024-55964 being actively exploited?
According to CISA's Known Exploited Vulnerabilities list, CVE-2024-55964 is not currently listed as actively exploited in the wild, and no public exploit code has been disclosed.
What versions of Docker are affected by CVE-2024-55964?
Appsmith versions prior to 1.52 are vulnerable. The vulnerability exists in the Appsmith application layer within Docker containers, not in Docker itself. Any deployment running Appsmith < 1.52 in a Docker container is at risk.
How do I check if my server is vulnerable to CVE-2024-55964?
Run `docker exec <appsmith_container_id> cat /opt/appsmith/package.json | grep -oP '"version":\s*"\K[^"]+' | head -1` to determine the installed version, then compare against 1.52. If the version is lower, your deployment is vulnerable.
Does Defensia detect CVE-2024-55964?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Appsmith is deployed in a monitored Docker environment, CVE-2024-55964 will appear in your dashboard with remediation steps and version mismatches.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-55964. Free for 1 server.
Get started free