Appsmith <= v1.97 instance management API endpoints are accessible without authentication, allowing an attacker to obtain sensitive information such as license plan, instance ID, authentication providers, feature flags, and configuration metadata via unauthenticated requests to specific API endpoints.
id: appsmith-info-disclosure
info:
name: Appsmith <= v1.97 - Information Disclosure
author: rit
...