VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 152 of 184
  • CVE-2024-25737MedMay 22, 2024
    risk 0.28cvss 5.4epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open Library Foundation VuFind 2.4 through 9.1 before 9.1.1 allows remote attackers to access internal HTTP servers and perform Cross-Site Scripting (XSS) attacks…

  • CVE-2024-34453MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).

  • CVE-2024-32812MedApr 24, 2024
    risk 0.28cvss 5.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.11.

  • CVE-2024-22329MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack.…

  • CVE-2024-27707MedMar 7, 2024
    risk 0.28cvss 4.3epss 0.00

    Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.

  • CVE-2023-47116MedJan 31, 2024
    risk 0.28cvss 5.3epss 0.01

    Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on version 1.8.2. Label Studio's SSRF protections that can be enabled by setting the `SSRF_PROTECTION_ENABLED` environment variable can…

  • CVE-2023-6070MedNov 29, 2023
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts…

  • CVE-2023-39301MedNov 3, 2023
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network. We have already fixed the vulnerability in the…

  • CVE-2023-44469MedSep 29, 2023
    risk 0.28cvss 4.3epss 0.01

    A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

  • CVE-2023-36388MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.

  • CVE-2023-36387MedSep 6, 2023
    risk 0.28cvss 5.4epss 0.01

    An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.

  • CVE-2023-26438MedAug 2, 2023
    risk 0.28cvss 4.3epss 0.01

    External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, involving the JDK DNS cache. Attackers that were timing DNS cache expiry correctly were able to inject configuration that would bypass existing network…

  • CVE-2023-25609MedJun 13, 2023
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially…

  • CVE-2023-30019MedMay 8, 2023
    risk 0.28cvss 5.3epss 0.02

    imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.

  • CVE-2018-17450MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

  • CVE-2022-43699MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.00

    OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).

  • CVE-2022-43698MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.00

    OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.

  • CVE-2022-27234MedFeb 16, 2023
    risk 0.28cvss 4.3epss 0.00

    Server-side request forgery in the CVAT software maintained by Intel(R) before version 2.0.1 may allow an authenticated user to potentially enable information disclosure via network access.

  • CVE-2022-4335MedJan 27, 2023
    risk 0.28cvss 4.3epss 0.01

    A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

  • CVE-2022-23464MedSep 24, 2022
    risk 0.28cvss 4.3epss 0.01

    Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses RestTemplate’s getForEntity to retrieve the contents of a URL containing user-controlled input, potentially resulting in…