VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 124 of 184
  • CVE-2023-32337MedJan 19, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: …

  • CVE-2023-50258MedDec 22, 2023
    risk 0.35cvss 5.3epss 0.01

    Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forgery (SSRF). The `testDiscord` request handler in `medusa/server/web/home/handler.py` does not validate the user-controlled…

  • CVE-2023-49795MedDec 11, 2023
    risk 0.35cvss 6.5epss 0.00

    MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which…

  • CVE-2023-35896MedNov 3, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.

  • CVE-2023-25753MedOct 19, 2023
    risk 0.35cvss 6.5epss 0.01

    There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl parameter. Of particular…

  • CVE-2023-35011MedAug 16, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID:…

  • CVE-2022-41401MedAug 4, 2023
    risk 0.35cvss 6.5epss 0.01

    OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, potentially leading to unauthorized access to internal resources and sensitive file disclosure.

  • CVE-2023-32052MedJul 11, 2023
    risk 0.35cvss 5.4epss 0.01

    Microsoft Power Apps (online) Spoofing Vulnerability

  • CVE-2022-37313MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

  • CVE-2022-38398MedSep 22, 2022
    risk 0.35cvss 5.3epss 0.03

    Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.

  • CVE-2022-32457MedJul 20, 2022
    risk 0.35cvss 5.3epss 0.01

    Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.

  • CVE-2022-22416MedJul 19, 2022
    risk 0.35cvss 5.4epss 0.00

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other…

  • CVE-2021-36761MedJun 21, 2022
    risk 0.35cvss 5.3epss 0.01

    The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.

  • CVE-2022-1285MedJun 1, 2022
    risk 0.35cvss 6.5epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

  • CVE-2021-36203MedApr 22, 2022
    risk 0.35cvss 5.3epss 0.01

    The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.

  • CVE-2022-0425MedApr 1, 2022
    risk 0.35cvss 5.4epss 0.01

    A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Server Side Request Forgery (SSRF) attacks.

  • CVE-2022-0136MedMar 28, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack through the Project Import feature.

  • CVE-2022-0528MedMar 3, 2022
    risk 0.35cvss 6.5epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

  • CVE-2021-36327MedNov 30, 2021
    risk 0.35cvss 5.3epss 0.01

    Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to perform port scanning of internal networks and make HTTP requests to an arbitrary domain of…

  • CVE-2021-3553MedNov 24, 2021
    risk 0.35cvss 5.3epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Tools versions prior to…