CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,679)
page 21 of 184| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-0539 | Hig | 0.57 | 8.8 | 0.00 | Apr 10, 2025 | In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host… | ||
| CVE-2025-22952 | Cri | 0.57 | 9.8 | 0.03 | Feb 27, 2025 | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | ||
| CVE-2025-21177 | Hig | 0.57 | 8.7 | 0.01 | Feb 6, 2025 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-12867 | Hig | 0.57 | — | 0.01 | Dec 20, 2024 | Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data. | ||
| CVE-2024-55875 | Cri | 0.57 | 9.8 | 0.02 | Dec 12, 2024 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive… | ||
| CVE-2024-47208 | Cri | 0.57 | 9.8 | 0.02 | Nov 18, 2024 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue. | ||
| CVE-2021-3742 | Hig | 0.57 | 8.8 | 0.00 | Nov 15, 2024 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used as an avatar and opened in a… | ||
| CVE-2023-37230 | Hig | 0.57 | 8.8 | 0.00 | Sep 10, 2024 | Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF. | ||
| CVE-2023-37229 | Hig | 0.57 | 8.8 | 0.00 | Sep 10, 2024 | Loftware Spectrum before 5.1 allows SSRF. | ||
| CVE-2024-40718 | Hig | 0.57 | 8.8 | 0.00 | Sep 7, 2024 | A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability. | ||
| CVE-2024-45258 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2024 | The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design. | ||
| CVE-2024-41120 | Cri | 0.57 | 9.8 | 0.01 | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which is later passed to the `gpd.read_file`… | ||
| CVE-2024-40544 | Hig | 0.57 | 8.8 | 0.00 | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit. | ||
| CVE-2024-40543 | Hig | 0.57 | 8.8 | 0.00 | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage. | ||
| CVE-2024-32407 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2024 | An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature. | ||
| CVE-2022-34269 | Hig | 0.57 | 8.8 | 0.02 | Feb 29, 2024 | An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution. | ||
| CVE-2023-42282 | Cri | 0.57 | 9.8 | 0.02 | Feb 8, 2024 | The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic. | ||
| CVE-2024-24113 | Hig | 0.57 | 8.8 | 0.01 | Feb 8, 2024 | xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE. | ||
| CVE-2023-6991 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2024 | The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks. | ||
| CVE-2023-49471 | Hig | 0.57 | 8.8 | 0.01 | Jan 10, 2024 | Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code. |
- risk 0.57cvss 8.8epss 0.00
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host…
- risk 0.57cvss 9.8epss 0.03
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
- risk 0.57cvss 8.7epss 0.01
Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss —epss 0.01
Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.
- risk 0.57cvss 9.8epss 0.02
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive…
- risk 0.57cvss 9.8epss 0.02
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
- risk 0.57cvss 8.8epss 0.00
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used as an avatar and opened in a…
- risk 0.57cvss 8.8epss 0.00
Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.
- risk 0.57cvss 8.8epss 0.00
Loftware Spectrum before 5.1 allows SSRF.
- risk 0.57cvss 8.8epss 0.00
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
- risk 0.57cvss 9.8epss 0.01
The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.
- risk 0.57cvss 9.8epss 0.01
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which is later passed to the `gpd.read_file`…
- risk 0.57cvss 8.8epss 0.00
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.
- risk 0.57cvss 8.8epss 0.00
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.
- risk 0.57cvss 8.8epss 0.01
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.
- risk 0.57cvss 9.8epss 0.02
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
- risk 0.57cvss 8.8epss 0.01
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
- risk 0.57cvss 8.8epss 0.01
The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.
- risk 0.57cvss 8.8epss 0.01
Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code.