CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,680)
page 23 of 184| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0766 | Cri | 0.57 | 9.8 | 0.01 | Mar 7, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | ||
| CVE-2022-23644 | Hig | 0.57 | 8.8 | 0.01 | Feb 16, 2022 | BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a… | ||
| CVE-2022-0339 | Cri | 0.57 | 9.8 | 0.01 | Jan 30, 2022 | Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. | ||
| CVE-2022-0086 | Cri | 0.57 | 9.8 | 0.01 | Jan 4, 2022 | uppy is vulnerable to Server-Side Request Forgery (SSRF) | ||
| CVE-2021-40809 | Hig | 0.57 | 8.8 | 0.01 | Dec 1, 2021 | An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows. | ||
| CVE-2021-43562 | Hig | 0.57 | 8.8 | 0.01 | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote… | ||
| CVE-2021-29844 | Hig | 0.57 | 8.8 | 0.01 | Oct 27, 2021 | IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | ||
| CVE-2021-32663 | Hig | 0.57 | 8.7 | 0.01 | Oct 19, 2021 | iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later | ||
| CVE-2021-23029 | — | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2021 | On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software… | |
| CVE-2021-32603 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2021 | A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system… | ||
| CVE-2021-1272 | Hig | 0.57 | 8.8 | 0.01 | Jan 20, 2021 | A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. This vulnerability is due to… | ||
| CVE-2020-28735 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2020 | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). | ||
| CVE-2020-28360 | Cri | 0.57 | 9.8 | 0.03 | Nov 23, 2020 | Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack… | ||
| CVE-2020-27197 | Cri | 0.57 | 9.8 | 0.02 | Oct 17, 2020 | TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method… | ||
| CVE-2020-13970 | Hig | 0.57 | 8.8 | 0.01 | Jul 28, 2020 | Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server. | ||
| CVE-2020-13379 | Hig | 0.57 | 8.2 | 1.00 | Jun 3, 2020 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information… | ||
| CVE-2014-8943 | Hig | 0.57 | 8.8 | 0.01 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter. | ||
| CVE-2020-8830 | Hig | 0.57 | 8.8 | 0.01 | May 5, 2020 | CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen. | ||
| CVE-2019-19261 | Hig | 0.57 | 8.8 | 0.01 | Jan 3, 2020 | GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF. | ||
| CVE-2019-17670 | Cri | 0.57 | 9.8 | 0.05 | Oct 17, 2019 | WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. |
- risk 0.57cvss 9.8epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
- risk 0.57cvss 8.8epss 0.01
BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a…
- risk 0.57cvss 9.8epss 0.01
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
- risk 0.57cvss 9.8epss 0.01
uppy is vulnerable to Server-Side Request Forgery (SSRF)
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote…
- risk 0.57cvss 8.8epss 0.01
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
- risk 0.57cvss 8.7epss 0.01
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later
- risk 0.57cvss 8.8epss 0.01
On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software…
- risk 0.57cvss 8.8epss 0.01
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system…
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. This vulnerability is due to…
- risk 0.57cvss 8.8epss 0.01
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
- risk 0.57cvss 9.8epss 0.03
Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack…
- risk 0.57cvss 9.8epss 0.02
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method…
- risk 0.57cvss 8.8epss 0.01
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
- risk 0.57cvss 8.2epss 1.00
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information…
- risk 0.57cvss 8.8epss 0.01
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
- risk 0.57cvss 8.8epss 0.01
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
- risk 0.57cvss 8.8epss 0.01
GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.
- risk 0.57cvss 9.8epss 0.05
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.