VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,631)

page 10 of 182
  • CVE-2020-10956CriMar 27, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

  • CVE-2019-11574CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.

  • CVE-2020-8135CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.01

    The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.

  • CVE-2020-10077CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.

  • CVE-2019-12443CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.

  • CVE-2020-10212CriMar 7, 2020
    risk 0.64cvss 9.8epss 0.01

    upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename…

  • CVE-2020-8128CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.03

    An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.

  • CVE-2020-3938CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.01

    SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests.

  • CVE-2019-5464CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

  • CVE-2019-16948CriNov 13, 2019
    risk 0.64cvss 9.8epss 0.01

    An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to determine what is visible on the internal network (as opposed to what general…

  • CVE-2019-18355CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.02

    An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.

  • CVE-2019-13335CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.01

    SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.

  • CVE-2019-15494CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.02

    openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.

  • CVE-2019-0345CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication…

  • CVE-2019-14255CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.02

    A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints.

  • CVE-2019-14704CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.

  • CVE-2019-12852CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.

  • CVE-2018-17198CriMay 28, 2019
    risk 0.64cvss 9.8epss 0.04

    Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens…

  • CVE-2017-13667CriMay 23, 2019
    risk 0.64cvss 9.9epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

  • CVE-2019-11066CriMay 10, 2019
    risk 0.64cvss 9.8epss 0.02

    openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.