VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 9 of 182
  • CVE-2021-39303CriNov 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability.

  • CVE-2021-39497CriSep 7, 2021
    risk 0.64cvss 9.8epss 0.02

    eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.

  • CVE-2021-37353CriAug 13, 2021
    risk 0.64cvss 9.8epss 0.03

    Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.

  • CVE-2020-24142CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open…

  • CVE-2021-35209CriJul 2, 2021
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is…

  • CVE-2021-31531CriJun 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).

  • CVE-2020-15377CriJun 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).

  • CVE-2017-17674CriMay 19, 2021
    risk 0.64cvss 9.8epss 0.02

    BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code…

  • CVE-2021-29145CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.02

    A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-1627CriMar 26, 2021
    risk 0.64cvss 9.8epss 0.01

    MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.

  • CVE-2020-23534CriFeb 25, 2021
    risk 0.64cvss 9.8epss 0.01

    A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.

  • CVE-2020-35205CriJan 11, 2021
    risk 0.64cvss 9.8epss 0.02

    Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported…

  • CVE-2020-35712CriDec 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.

  • CVE-2020-25466CriOct 23, 2020
    risk 0.64cvss 9.8epss 0.03

    A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

  • CVE-2020-14056CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.01

    Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.

  • CVE-2020-13484CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.02

    Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.

  • CVE-2020-4101CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.01

    "HCL Digital Experience is susceptible to Server Side Request Forgery."

  • CVE-2020-6275CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions…

  • CVE-2020-13226CriMay 20, 2020
    risk 0.64cvss 9.8epss 0.02

    WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.

  • CVE-2020-10980CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.02

    GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.