VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 91 of 185
  • CVE-2021-20483MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.

  • CVE-2021-33571HigJun 8, 2021
    risk 0.42cvss 7.5epss 0.05

    In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses.…

  • CVE-2020-28943MedApr 30, 2021
    risk 0.42cvss 6.5epss 0.01

    OX App Suite 7.10.4 and earlier allows SSRF via a snippet.

  • CVE-2021-31779MedApr 28, 2021
    risk 0.42cvss 6.4epss 0.00

    The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.

  • CVE-2021-20480MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.

  • CVE-2021-22696HigApr 2, 2021
    risk 0.42cvss 7.5epss 0.07

    CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also…

  • CVE-2020-15809MedMar 24, 2021
    risk 0.42cvss 6.5epss 0.01

    spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.

  • CVE-2021-3204MedFeb 19, 2021
    risk 0.42cvss 6.5epss 0.01

    SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the server.

  • CVE-2020-28463MedFeb 18, 2021
    risk 0.42cvss 6.5epss 0.01

    All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of…

  • CVE-2020-36200MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.01

    TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.

  • CVE-2021-23927MedJan 12, 2021
    risk 0.42cvss 6.4epss 0.01

    OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

  • CVE-2020-35850MedDec 30, 2020
    risk 0.42cvss 6.5epss 0.02

    An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.

  • CVE-2019-14476MedDec 16, 2020
    risk 0.42cvss 6.5epss 0.01

    AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.

  • CVE-2020-24815MedNov 24, 2020
    risk 0.42cvss 6.5epss 0.02

    A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML containers embedded…

  • CVE-2020-5784MedOct 1, 2020
    risk 0.42cvss 6.5epss 0.01

    Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.

  • CVE-2020-24570MedSep 30, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.

  • CVE-2020-4632MedSep 4, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416.

  • CVE-2020-17386MedAug 25, 2020
    risk 0.42cvss 6.5epss 0.01

    Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.

  • CVE-2020-13286MedAug 13, 2020
    risk 0.42cvss 6.4epss 0.01

    For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.

  • CVE-2020-8544MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    OX App Suite through 7.10.3 allows SSRF.