CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,680)
page 126 of 184| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22179 | Med | 0.35 | 5.4 | 0.01 | Mar 24, 2021 | A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature. | ||
| CVE-2021-23345 | Med | 0.35 | 5.3 | 0.01 | Feb 26, 2021 | All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as . | ||
| CVE-2020-35561 | Med | 0.35 | 5.3 | 0.01 | Feb 16, 2021 | An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports. | ||
| CVE-2021-25241 | Med | 0.35 | 5.3 | 0.02 | Feb 4, 2021 | A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep. | ||
| CVE-2021-25236 | Med | 0.35 | 5.3 | 0.02 | Feb 4, 2021 | A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep. | ||
| CVE-2020-24700 | Med | 0.35 | 5.4 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring. | ||
| CVE-2020-27626 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. | ||
| CVE-2020-27624 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. | ||
| CVE-2020-26811 | Med | 0.35 | 5.3 | 0.02 | Nov 10, 2020 | SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads… | ||
| CVE-2020-13309 | Med | 0.35 | 5.4 | 0.01 | Sep 14, 2020 | A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature. | ||
| CVE-2020-24548 | Med | 0.35 | 5.3 | 0.02 | Aug 26, 2020 | Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports. | ||
| CVE-2020-13295 | Med | 0.35 | 5.4 | 0.01 | Aug 10, 2020 | For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF. | ||
| CVE-2020-15819 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports. | ||
| CVE-2019-20408 | Med | 0.35 | 5.3 | 0.01 | Jul 1, 2020 | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class. | ||
| CVE-2020-11453 | Med | 0.35 | 5.3 | 0.03 | Apr 2, 2020 | Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and, while it is not possible to pass parameters in the SSRF request, it is still… | ||
| CVE-2019-4741 | Med | 0.35 | 5.3 | 0.01 | Feb 12, 2020 | IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815. | ||
| CVE-2019-14225 | Med | 0.35 | 5.4 | 0.01 | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows SSRF. | ||
| CVE-2019-15021 | Med | 0.35 | 5.3 | 0.01 | Oct 9, 2019 | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingbox Inspectors in a local area network. | ||
| CVE-2019-15164 | Med | 0.35 | 5.3 | 0.03 | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source. | ||
| CVE-2019-4262 | Med | 0.35 | 5.3 | 0.01 | Sep 26, 2019 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014. |
- risk 0.35cvss 5.4epss 0.01
A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.
- risk 0.35cvss 5.3epss 0.01
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as .
- risk 0.35cvss 5.3epss 0.01
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.
- risk 0.35cvss 5.3epss 0.02
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.
- risk 0.35cvss 5.3epss 0.02
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.
- risk 0.35cvss 5.4epss 0.01
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.02
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads…
- risk 0.35cvss 5.4epss 0.01
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.
- risk 0.35cvss 5.3epss 0.02
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.
- risk 0.35cvss 5.4epss 0.01
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
- risk 0.35cvss 5.3epss 0.01
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
- risk 0.35cvss 5.3epss 0.03
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and, while it is not possible to pass parameters in the SSRF request, it is still…
- risk 0.35cvss 5.3epss 0.01
IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815.
- risk 0.35cvss 5.4epss 0.01
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
- risk 0.35cvss 5.3epss 0.01
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingbox Inspectors in a local area network.
- risk 0.35cvss 5.3epss 0.03
rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
- risk 0.35cvss 5.3epss 0.01
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.