VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 92 of 185
  • CVE-2020-10791MedMar 25, 2020
    risk 0.42cvss 6.5epss 0.01

    app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.

  • CVE-2020-8138MedMar 20, 2020
    risk 0.42cvss 6.5epss 0.01

    A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

  • CVE-2019-20055MedDec 29, 2019
    risk 0.42cvss 6.5epss 0.01

    LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

  • CVE-2019-17400HigOct 21, 2019
    risk 0.42cvss 7.5epss 0.02

    The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.

  • CVE-2018-19495MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

  • CVE-2019-3809MedMar 25, 2019
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests…

  • CVE-2019-6970HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.01

    Moodle 3.5.x before 3.5.4 allows SSRF.

  • CVE-2018-12609MedJan 30, 2019
    risk 0.42cvss 6.5epss 0.01

    OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.

  • CVE-2018-1000421MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained…

  • CVE-2018-20528MedDec 28, 2018
    risk 0.42cvss 6.5epss 0.01

    JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.

  • CVE-2018-19651MedNov 28, 2018
    risk 0.42cvss 6.5epss 0.01

    admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL. This also allows reading local files with a file: URL.

  • CVE-2017-16790MedAug 6, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This big array forms the data that…

  • CVE-2018-9920MedMay 24, 2018
    risk 0.42cvss 6.5epss 0.01

    Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.

  • CVE-2018-8801MedApr 25, 2018
    risk 0.42cvss 6.5epss 0.01

    GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

  • CVE-2018-10174MedApr 20, 2018
    risk 0.42cvss 6.5epss 0.01

    Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.

  • CVE-2017-15886MedDec 28, 2017
    risk 0.42cvss 6.5epss 0.02

    Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.

  • CVE-2017-12071MedSep 8, 2017
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.

  • CVE-2017-11149MedAug 14, 2017
    risk 0.42cvss 6.5epss 0.02

    Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.

  • CVE-2017-11148MedAug 11, 2017
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.

  • CVE-2017-10973MedJul 6, 2017
    risk 0.42cvss 6.5epss 0.01

    In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header.