CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,632)
page 182 of 182| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1784 | Hig | 0.00 | 7.5 | 0.02 | May 20, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8. | ||
| CVE-2022-1767 | Hig | 0.00 | 7.5 | 0.02 | May 18, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7. | ||
| CVE-2022-1711 | Hig | 0.00 | 7.5 | 0.06 | May 17, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5. | ||
| CVE-2022-1723 | Hig | 0.00 | 7.5 | 0.02 | May 17, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6. | ||
| CVE-2022-1722 | Low | 0.00 | 3.3 | 0.01 | May 16, 2022 | SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses | ||
| CVE-2022-1379 | Cri | 0.00 | 9.1 | 0.02 | May 14, 2022 | URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal… | ||
| CVE-2022-0990 | Cri | 0.00 | 9.1 | 0.01 | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | ||
| CVE-2022-0939 | Cri | 0.00 | 9.9 | 0.01 | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | ||
| CVE-2022-1191 | Hig | 0.00 | 8.1 | 0.01 | Mar 31, 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. | ||
| CVE-2022-0132 | Hig | 0.00 | 7.5 | 0.01 | Jan 10, 2022 | peertube is vulnerable to Server-Side Request Forgery (SSRF) | ||
| CVE-2015-1775 | 0.00 | — | 0.03 | Nov 2, 2015 | Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call. | |||
| CVE-2013-6919 | 0.00 | — | 0.01 | Dec 27, 2014 | The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter. |
- risk 0.00cvss 7.5epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.
- risk 0.00cvss 7.5epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.
- risk 0.00cvss 7.5epss 0.06
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.
- risk 0.00cvss 7.5epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.
- risk 0.00cvss 3.3epss 0.01
SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses
- risk 0.00cvss 9.1epss 0.02
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal…
- risk 0.00cvss 9.1epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
- risk 0.00cvss 9.9epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
- risk 0.00cvss 8.1epss 0.01
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- risk 0.00cvss 7.5epss 0.01
peertube is vulnerable to Server-Side Request Forgery (SSRF)
- CVE-2015-1775Nov 2, 2015risk 0.00cvss —epss 0.03
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
- CVE-2013-6919Dec 27, 2014risk 0.00cvss —epss 0.01
The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter.