VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 160 of 162
  • CVE-2022-38298HigSep 12, 2022
    risk 0.00cvss 8.8epss 0.01

    Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.

  • CVE-2022-31196HigSep 2, 2022
    risk 0.00cvss 7.6epss 0.01

    Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerability. The SSRF is triggered by a sending a **single** HTTP POST request to create a databaseType. By supplying a `jdbcDriverFileUrl` that returns a non `200`…

  • CVE-2021-27693CriSep 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.

  • CVE-2022-2756MedAug 10, 2022
    risk 0.00cvss 6.5epss 0.03

    Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.

  • CVE-2022-35651MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.01

    A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…

  • CVE-2022-2339HigJul 7, 2022
    risk 0.00cvss 7.5epss 0.02

    With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.

  • CVE-2022-25876MedJul 1, 2022
    risk 0.00cvss 6.2epss 0.00

    The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

  • CVE-2022-23071MedJun 19, 2022
    risk 0.00cvss 6.5epss 0.01

    In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information.

  • CVE-2022-1815HigMay 25, 2022
    risk 0.00cvss 7.5epss 0.06

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

  • CVE-2022-1784HigMay 20, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.

  • CVE-2022-1767HigMay 18, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.

  • CVE-2022-1711HigMay 17, 2022
    risk 0.00cvss 7.5epss 0.06

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

  • CVE-2022-1723HigMay 17, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.

  • CVE-2022-1722LowMay 16, 2022
    risk 0.00cvss 3.3epss 0.01

    SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses

  • CVE-2022-1379CriMay 14, 2022
    risk 0.00cvss 9.1epss 0.02

    URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal…

  • CVE-2022-0990CriApr 4, 2022
    risk 0.00cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

  • CVE-2022-0939CriApr 4, 2022
    risk 0.00cvss 9.9epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

  • CVE-2022-1191HigMar 31, 2022
    risk 0.00cvss 8.1epss 0.01

    SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.

  • CVE-2021-25939LowFeb 9, 2022
    risk 0.00cvss 2.7epss 0.01

    In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to…

  • CVE-2021-45325HigFeb 8, 2022
    risk 0.00cvss 7.5epss 0.01

    Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.