VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 90 of 185
  • CVE-2022-29631HigJun 6, 2022
    risk 0.42cvss 7.5epss 0.01

    Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

  • CVE-2021-40186MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.01

    The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of…

  • CVE-2022-1398MedMay 16, 2022
    risk 0.42cvss 6.5epss 0.03

    The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks

  • CVE-2022-29942MedMay 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' functionality to perform SSRF HTTP GET requests on URLs in the internal network. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175,…

  • CVE-2022-28090MedMay 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.

  • CVE-2022-25850HigMay 1, 2022
    risk 0.42cvss 7.5epss 0.01

    The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of…

  • CVE-2020-27375MedApr 7, 2022
    risk 0.42cvss 6.5epss 0.01

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

  • CVE-2022-27201MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file…

  • CVE-2021-39051MedMar 14, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the…

  • CVE-2022-24333MedFeb 25, 2022
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.

  • CVE-2022-24980HigFeb 19, 2022
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF,…

  • CVE-2022-23206HigFeb 6, 2022
    risk 0.42cvss 7.5epss 0.02

    In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.

  • CVE-2021-35512MedOct 21, 2021
    risk 0.42cvss 6.5epss 0.02

    An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

  • CVE-2021-39867MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

  • CVE-2021-40109MedSep 27, 2021
    risk 0.42cvss 6.4epss 0.01

    A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and…

  • CVE-2021-41385MedSep 27, 2021
    risk 0.42cvss 6.5epss 0.01

    The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF.

  • CVE-2021-21993MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.01

    The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to…

  • CVE-2021-3758MedSep 2, 2021
    risk 0.42cvss 6.5epss 0.01

    bookstack is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2020-25353MedAug 20, 2021
    risk 0.42cvss 6.5epss 0.01

    A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the deviceIpAddr and connPort parameters.

  • CVE-2021-33213MedJul 14, 2021
    risk 0.42cvss 6.5epss 0.01

    An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP files from the internal server network by inserting an internal address.