CWE-918
Server-Side Request Forgery (SSRF)
Description
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-664
CVEs mapped to this weakness (3,621)
page 9 of 182| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39303 | Cri | 0.64 | 9.8 | 0.02 | Nov 12, 2021 | The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability. | ||
| CVE-2021-39497 | Cri | 0.64 | 9.8 | 0.02 | Sep 7, 2021 | eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function. | ||
| CVE-2021-37353 | Cri | 0.64 | 9.8 | 0.03 | Aug 13, 2021 | Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php. | ||
| CVE-2020-24142 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2021 | Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open… | ||
| CVE-2021-35209 | Cri | 0.64 | 9.8 | 0.03 | Jul 2, 2021 | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is… | ||
| CVE-2021-31531 | Cri | 0.64 | 9.8 | 0.02 | Jun 29, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). | ||
| CVE-2020-15377 | Cri | 0.64 | 9.8 | 0.01 | Jun 9, 2021 | Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF). | ||
| CVE-2017-17674 | Cri | 0.64 | 9.8 | 0.02 | May 19, 2021 | BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code… | ||
| CVE-2021-29145 | Cri | 0.64 | 9.8 | 0.02 | Apr 29, 2021 | A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability. | ||
| CVE-2021-1627 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2021 | MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021. | ||
| CVE-2020-23534 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2021 | A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter. | ||
| CVE-2020-35205 | Cri | 0.64 | 9.8 | 0.02 | Jan 11, 2021 | Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported… | ||
| CVE-2020-35712 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2020 | Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations. | ||
| CVE-2020-25466 | Cri | 0.64 | 9.8 | 0.03 | Oct 23, 2020 | A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. | ||
| CVE-2020-14056 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2020 | Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services. | ||
| CVE-2020-13484 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2020 | Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL. | ||
| CVE-2020-4101 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2020 | "HCL Digital Experience is susceptible to Server Side Request Forgery." | ||
| CVE-2020-6275 | Cri | 0.64 | 9.8 | 0.01 | Jun 10, 2020 | SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions… | ||
| CVE-2020-13226 | — | Cri | 0.64 | 9.8 | 0.02 | May 20, 2020 | WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet. | |
| CVE-2020-10980 | Cri | 0.64 | 9.8 | 0.02 | Apr 8, 2020 | GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration. |
- risk 0.64cvss 9.8epss 0.02
The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability.
- risk 0.64cvss 9.8epss 0.02
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
- risk 0.64cvss 9.8epss 0.03
Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.
- risk 0.64cvss 9.8epss 0.02
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is…
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
- risk 0.64cvss 9.8epss 0.01
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).
- risk 0.64cvss 9.8epss 0.02
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code…
- risk 0.64cvss 9.8epss 0.02
A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.
- risk 0.64cvss 9.8epss 0.01
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.
- risk 0.64cvss 9.8epss 0.01
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
- risk 0.64cvss 9.8epss 0.02
Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported…
- risk 0.64cvss 9.8epss 0.02
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
- risk 0.64cvss 9.8epss 0.03
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.
- risk 0.64cvss 9.8epss 0.02
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
- risk 0.64cvss 9.8epss 0.01
"HCL Digital Experience is susceptible to Server Side Request Forgery."
- risk 0.64cvss 9.8epss 0.01
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions…
- risk 0.64cvss 9.8epss 0.02
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
- risk 0.64cvss 9.8epss 0.02
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.