Rhino Security Labs

Strategic & Technical Blog

CVE-2024-55963: Unauthenticated RCE in Default-Install of Appsmith

Whit Taylor
March 25, 2025

While reviewing the Appsmith Enterprise platform, Rhino Security Labs uncovered a series of critical vulnerabilities affecting default installations of the product. Most severe among them is CVE-2024-55963, which allows unauthenticated…

CVE-2025-0693: AWS IAM User Enumeration

CVE-2024-46506: Unauthenticated RCE in NetAlertx

CVE-2024-46507: Yeti Platform
Server-Side Template Injection (SSTI)

Chebuya

Yeti is a Forensic Intelligence platform and pipeline for DFIR teams. It allows threat intelligence and DFIR teams to catalog, search, and link pieces of intelligence such as IP addresses, TTPs, and threat actors. With 10,000 pulls from…