CWE-918
2,678 CVEs • Abstraction: Base
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CVEs (2,678)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows. |
1Dell 1Emc Streaming Data Platform Nov 21, 2024 Nov 30, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to perform port scanning of internal...Show more |
1Zohocorp 1Manageengine Supportcenter Plus Nov 21, 2024 Nov 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. |
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit t...Show more |
Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanced methods of Server Side Request Forgery...Show more |
1Bitdefender 2Endpoint Security Tools GravityzoneNov 21, 2024 Nov 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects...Show more |
1Bitdefender 2Endpoint Security Tools GravityzoneNov 21, 2024 Nov 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoi...Show more |
1Ssrf Agent Project 1Ssrf Agent Nov 21, 2024 Nov 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is private. |
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN....Show more |
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows d...Show more |
The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability. |
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a resul...Show more |
1Sonatype 1Nexus Repository Manager Nov 21, 2024 Nov 4, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF). |
1Ibm 1Infosphere Information Server Nov 21, 2024 Nov 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pot...Show more |
1Ibm 7Engineering Lifecycle Optimization Engineering Requirements Quality Assistant On PremisesEngineering Workflow Management+4 moreNov 21, 2024 Oct 27, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or fac...Show more |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 Oct 21, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. |
1Alfresco 2Alfresco Content Services Alfresco Transform ServicesNov 21, 2024 Oct 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request...Show more |
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs re...Show more |
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolve...Show more |
1Vmware 3Cloud Foundation Vrealize OperationsVrealize Suite Lifecycle ManagerNov 21, 2024 Oct 13, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. |