VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,632)

page 182 of 182
  • CVE-2022-1784HigMay 20, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.

  • CVE-2022-1767HigMay 18, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.

  • CVE-2022-1711HigMay 17, 2022
    risk 0.00cvss 7.5epss 0.06

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

  • CVE-2022-1723HigMay 17, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.

  • CVE-2022-1722LowMay 16, 2022
    risk 0.00cvss 3.3epss 0.01

    SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses

  • CVE-2022-1379CriMay 14, 2022
    risk 0.00cvss 9.1epss 0.02

    URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal…

  • CVE-2022-0990CriApr 4, 2022
    risk 0.00cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

  • CVE-2022-0939CriApr 4, 2022
    risk 0.00cvss 9.9epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

  • CVE-2022-1191HigMar 31, 2022
    risk 0.00cvss 8.1epss 0.01

    SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.

  • CVE-2022-0132HigJan 10, 2022
    risk 0.00cvss 7.5epss 0.01

    peertube is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2015-1775Nov 2, 2015
    risk 0.00cvss —epss 0.03

    Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

  • CVE-2013-6919Dec 27, 2014
    risk 0.00cvss —epss 0.01

    The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter.