CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,621)
page 49 of 182| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27780 | Hig | 0.49 | 7.5 | 0.02 | Jun 2, 2022 | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe… | ||
| CVE-2022-29309 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2022 | mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery. | ||
| CVE-2022-28997 | Hig | 0.49 | 7.5 | 0.02 | May 23, 2022 | CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/. | ||
| CVE-2022-30049 | Hig | 0.49 | 7.5 | 0.01 | May 15, 2022 | A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet information via the fileurl parameter. | ||
| CVE-2022-29153 | Hig | 0.49 | 7.5 | 0.09 | Apr 19, 2022 | HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5. | ||
| CVE-2022-24789 | Hig | 0.49 | 7.6 | 0.01 | Mar 28, 2022 | C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The… | ||
| CVE-2021-44139 | Hig | 0.49 | 7.5 | 0.06 | Mar 23, 2022 | Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). | ||
| CVE-2021-46107 | Hig | 0.49 | 7.5 | 0.07 | Mar 17, 2022 | Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features. | ||
| CVE-2021-45851 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2022 | A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server. | ||
| CVE-2021-23664 | Hig | 0.49 | 8.6 | 0.01 | Jan 21, 2022 | The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js. | ||
| CVE-2021-22056 | Hig | 0.49 | 7.5 | 0.02 | Dec 20, 2021 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. | ||
| CVE-2021-43296 | Hig | 0.49 | 7.5 | 0.03 | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. | ||
| CVE-2021-22970 | Hig | 0.49 | 7.5 | 0.01 | Nov 19, 2021 | Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local… | ||
| CVE-2021-37104 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2021 | There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient validation of parameters while dealing with some messages. A successful exploit could allow the attacker to gain access to certain… | ||
| CVE-2021-41587 | Hig | 0.49 | 7.5 | 0.01 | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources. | ||
| CVE-2021-41586 | Hig | 0.49 | 7.5 | 0.01 | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password. | ||
| CVE-2021-37419 | Hig | 0.49 | 7.5 | 0.02 | Sep 21, 2021 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. | ||
| CVE-2021-28910 | Hig | 0.49 | 7.5 | 0.01 | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal and external server. | ||
| CVE-2020-20341 | Hig | 0.49 | 7.5 | 0.01 | Sep 1, 2021 | YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. | ||
| CVE-2021-22027 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information… |
- risk 0.49cvss 7.5epss 0.02
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe…
- risk 0.49cvss 7.5epss 0.01
mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.
- risk 0.49cvss 7.5epss 0.02
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.
- risk 0.49cvss 7.5epss 0.01
A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet information via the fileurl parameter.
- risk 0.49cvss 7.5epss 0.09
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
- risk 0.49cvss 7.6epss 0.01
C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The…
- risk 0.49cvss 7.5epss 0.06
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
- risk 0.49cvss 7.5epss 0.07
Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features.
- risk 0.49cvss 7.5epss 0.01
A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server.
- risk 0.49cvss 8.6epss 0.01
The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.
- risk 0.49cvss 7.5epss 0.02
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
- risk 0.49cvss 7.5epss 0.03
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
- risk 0.49cvss 7.5epss 0.01
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local…
- risk 0.49cvss 7.5epss 0.01
There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient validation of parameters while dealing with some messages. A successful exploit could allow the attacker to gain access to certain…
- risk 0.49cvss 7.5epss 0.01
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
- risk 0.49cvss 7.5epss 0.01
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.
- risk 0.49cvss 7.5epss 0.02
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
- risk 0.49cvss 7.5epss 0.01
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal and external server.
- risk 0.49cvss 7.5epss 0.01
YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
- risk 0.49cvss 7.5epss 0.01
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information…