CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,631)
page 10 of 182| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10956 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2020 | GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. | ||
| CVE-2019-11574 | Cri | 0.64 | 9.8 | 0.01 | Mar 20, 2020 | An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls. | ||
| CVE-2020-8135 | Cri | 0.64 | 9.8 | 0.01 | Mar 20, 2020 | The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems. | ||
| CVE-2020-10077 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2020 | GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk. | ||
| CVE-2019-12443 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks. | ||
| CVE-2020-10212 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2020 | upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename… | ||
| CVE-2020-8128 | Cri | 0.64 | 9.8 | 0.03 | Feb 14, 2020 | An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code. | ||
| CVE-2020-3938 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2020 | SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests. | ||
| CVE-2019-5464 | Cri | 0.64 | 9.8 | 0.03 | Jan 28, 2020 | A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized. | ||
| CVE-2019-16948 | Cri | 0.64 | 9.8 | 0.01 | Nov 13, 2019 | An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to determine what is visible on the internal network (as opposed to what general… | ||
| CVE-2019-18355 | Cri | 0.64 | 9.8 | 0.02 | Oct 23, 2019 | An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7. | ||
| CVE-2019-13335 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2019 | SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF. | ||
| CVE-2019-15494 | Cri | 0.64 | 9.8 | 0.02 | Aug 23, 2019 | openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. | ||
| CVE-2019-0345 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication… | ||
| CVE-2019-14255 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2019 | A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints. | ||
| CVE-2019-14704 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2019 | An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field. | ||
| CVE-2019-12852 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168. | ||
| CVE-2018-17198 | Cri | 0.64 | 9.8 | 0.04 | May 28, 2019 | Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens… | ||
| CVE-2017-13667 | Cri | 0.64 | 9.9 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF. | ||
| CVE-2019-11066 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2019 | openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method. |
- risk 0.64cvss 9.8epss 0.01
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
- risk 0.64cvss 9.8epss 0.01
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
- risk 0.64cvss 9.8epss 0.01
GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.
- risk 0.64cvss 9.8epss 0.01
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename…
- risk 0.64cvss 9.8epss 0.03
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests.
- risk 0.64cvss 9.8epss 0.03
A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.
- risk 0.64cvss 9.8epss 0.01
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to determine what is visible on the internal network (as opposed to what general…
- risk 0.64cvss 9.8epss 0.02
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
- risk 0.64cvss 9.8epss 0.01
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
- risk 0.64cvss 9.8epss 0.02
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
- risk 0.64cvss 9.8epss 0.02
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication…
- risk 0.64cvss 9.8epss 0.02
A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints.
- risk 0.64cvss 9.8epss 0.02
An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.
- risk 0.64cvss 9.8epss 0.02
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
- risk 0.64cvss 9.8epss 0.04
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens…
- risk 0.64cvss 9.9epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- risk 0.64cvss 9.8epss 0.02
openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.