VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 161 of 162
  • CVE-2022-0132HigJan 10, 2022
    risk 0.00cvss 7.5epss 0.01

    peertube is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2021-27738HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.03

    All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning of streaming…

  • CVE-2021-43780MedNov 24, 2021
    risk 0.00cvss 6.8epss 0.01

    Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanced methods of Server Side Request Forgery (SSRF). These vulnerabilities are only exploitable on…

  • CVE-2021-32663HigOct 19, 2021
    risk 0.00cvss 8.7epss 0.01

    iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later

  • CVE-2021-22958CriOct 7, 2021
    risk 0.00cvss 9.8epss 0.01

    A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0…

  • CVE-2020-24327MedSep 23, 2021
    risk 0.00cvss 5.3epss 0.01

    Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.

  • CVE-2021-39195HigSep 7, 2021
    risk 0.00cvss 7.7epss 0.01

    Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information within the internal…

  • CVE-2021-3758MedSep 2, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2020-14160HigAug 26, 2021
    risk 0.00cvss 7.5epss 0.02

    An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.

  • CVE-2021-32698MedJun 21, 2021
    risk 0.00cvss 6.8epss 0.01

    eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.

  • CVE-2021-31828HigMay 6, 2021
    risk 0.00cvss 7.1epss 0.01

    An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.

  • CVE-2021-29475CriApr 26, 2021
    risk 0.00cvss 10.0epss 0.01

    HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note content, there fore this exploit requires the…

  • CVE-2020-9298HigAug 28, 2020
    risk 0.00cvss 7.5epss 0.01

    The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.

  • CVE-2020-15879HigJul 21, 2020
    risk 0.00cvss 7.5epss 0.03

    Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).

  • CVE-2020-8205HigJul 20, 2020
    risk 0.00cvss 7.5epss 0.01

    The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.

  • CVE-2020-8555MedJun 5, 2020
    risk 0.00cvss 6.3epss 0.04

    The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from…

  • CVE-2020-10791MedMar 25, 2020
    risk 0.00cvss 6.5epss 0.01

    app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.

  • CVE-2019-15164MedOct 3, 2019
    risk 0.00cvss 5.3epss 0.03

    rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.

  • CVE-2019-11565CriApr 27, 2019
    risk 0.00cvss 9.8epss 0.03

    Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.

  • CVE-2019-3809MedMar 25, 2019
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests…