VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 88 of 185
  • CVE-2024-0403MedMar 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.

  • CVE-2024-1965MedFeb 28, 2024
    risk 0.42cvss 6.5epss 0.00

    Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve…

  • CVE-2024-23838HigJan 30, 2024
    risk 0.42cvss 7.5epss 0.01

    TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or…

  • CVE-2024-21642HigJan 5, 2024
    risk 0.42cvss 7.5epss 0.01

    D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0, where the `Load From the…

  • CVE-2023-7078HigDec 29, 2023
    risk 0.42cvss 7.5epss 0.01

    Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the…

  • CVE-2023-6570MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

  • CVE-2023-49799HigDec 9, 2023
    risk 0.42cvss 7.5epss 0.01

    `nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent the aforementioned attack. This has been recently changed to use the regular expression `^https?://`, however this regular…

  • CVE-2023-6199MedNov 20, 2023
    risk 0.42cvss 6.5epss 0.01

    Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.

  • CVE-2023-48204MedNov 16, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.

  • CVE-2023-41239MedNov 13, 2023
    risk 0.42cvss 6.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin by Blubrry: from n/a through 11.0.6.

  • CVE-2023-32786HigOct 20, 2023
    risk 0.42cvss 7.5epss 0.01

    In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.

  • CVE-2023-44256MedOct 20, 2023
    risk 0.42cvss 6.5epss 0.01

    A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive…

  • CVE-2023-42477MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.00

    SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.

  • CVE-2023-39854MedOct 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.

  • CVE-2023-42439HigSep 15, 2023
    risk 0.42cvss 7.5epss 0.01

    GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists starting in version 3.2.0, bypassing existing controls on the software. This can allow a user to request internal services for a full…

  • CVE-2023-4893MedSep 12, 2023
    risk 0.42cvss 6.4epss 0.00

    The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to…

  • CVE-2023-40017HigAug 24, 2023
    risk 0.42cvss 7.5epss 0.01

    GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2, the endpoint `/proxy/?url=` does not properly protect against server-side request forgery. This allows an attacker to port scan…

  • CVE-2023-29260MedJul 19, 2023
    risk 0.42cvss 6.5epss 0.00

    IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: …

  • CVE-2023-23169MedMay 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.

  • CVE-2023-24954MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft SharePoint Server Information Disclosure Vulnerability