VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 23 of 184
  • CVE-2022-0766CriMar 7, 2022
    risk 0.57cvss 9.8epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

  • CVE-2022-23644HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.01

    BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a…

  • CVE-2022-0339CriJan 30, 2022
    risk 0.57cvss 9.8epss 0.01

    Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.

  • CVE-2022-0086CriJan 4, 2022
    risk 0.57cvss 9.8epss 0.01

    uppy is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2021-40809HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows.

  • CVE-2021-43562HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote…

  • CVE-2021-29844HigOct 27, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2021-32663HigOct 19, 2021
    risk 0.57cvss 8.7epss 0.01

    iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later

  • CVE-2021-23029HigSep 14, 2021
    risk 0.57cvss 8.8epss 0.01

    On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software…

  • CVE-2021-32603HigAug 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system…

  • CVE-2021-1272HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. This vulnerability is due to…

  • CVE-2020-28735HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.01

    Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).

  • CVE-2020-28360CriNov 23, 2020
    risk 0.57cvss 9.8epss 0.03

    Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack…

  • CVE-2020-27197CriOct 17, 2020
    risk 0.57cvss 9.8epss 0.02

    TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method…

  • CVE-2020-13970HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.01

    Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

  • CVE-2020-13379HigJun 3, 2020
    risk 0.57cvss 8.2epss 1.00

    The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information…

  • CVE-2014-8943HigJun 1, 2020
    risk 0.57cvss 8.8epss 0.01

    Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.

  • CVE-2020-8830HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

  • CVE-2019-19261HigJan 3, 2020
    risk 0.57cvss 8.8epss 0.01

    GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

  • CVE-2019-17670CriOct 17, 2019
    risk 0.57cvss 9.8epss 0.05

    WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.