VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 154 of 184
  • CVE-2020-21788MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.

  • CVE-2021-33510MedMay 21, 2021
    risk 0.28cvss 4.3epss 0.01

    Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.

  • CVE-2020-29445MedMay 7, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.

  • CVE-2020-4786MedJan 27, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration…

  • CVE-2020-17513MedDec 14, 2020
    risk 0.28cvss 5.3epss 0.04

    In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

  • CVE-2020-24710MedOct 28, 2020
    risk 0.28cvss 5.3epss 0.01

    Gophish before 0.11.0 allows SSRF attacks.

  • CVE-2020-15594MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.02

    An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the…

  • CVE-2020-13788MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.01

    Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

  • CVE-2020-14170MedJul 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2020-4365MedMay 14, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.

  • CVE-2020-11452MedApr 2, 2020
    risk 0.28cvss 4.3epss 0.01

    Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the…

  • CVE-2019-20474MedFeb 17, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network…

  • CVE-2017-15029MedMay 23, 2019
    risk 0.28cvss 4.3epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

  • CVE-2019-1003028MedFeb 20, 2019
    risk 0.28cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins JMS Messaging Plugin 1.1.1 and earlier in SSLCertificateAuthenticationMethod.java, UsernameAuthenticationMethod.java that allows attackers with Overall/Read permission to have Jenkins connect to a JMS endpoint.

  • CVE-2019-1003027MedFeb 20, 2019
    risk 0.28cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL and obtain the HTTP response code if…

  • CVE-2019-1003026MedFeb 20, 2019
    risk 0.28cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in MattermostNotifier.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified Mattermost server and room and send a…

  • CVE-2019-1003020MedFeb 6, 2019
    risk 0.28cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL.

  • CVE-2018-1999039MedAug 1, 2018
    risk 0.28cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins Confluence Publisher Plugin 2.0.1 and earlier in ConfluenceSite.java that allows attackers to have Jenkins submit login requests to an attacker-specified Confluence server URL with attacker specified credentials.

  • CVE-2018-1000188MedJun 5, 2018
    risk 0.28cvss 5.4epss 0.01

    A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

  • CVE-2018-1000184MedJun 5, 2018
    risk 0.28cvss 5.4epss 0.01

    A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.