← Back
CWE-918

3,430 CVEs • Abstraction: Base

Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

JSON object

Loading...

CVEs (3,430)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jeecms
1Jeecms
Nov 21, 2024
Dec 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.
1Telegram
2Telegram
Web
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET...Show more
The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET requests to other URLs on the same web server. This also affects one or more other Telegram products, such as Telegram Web-version 0.7.0. In addition, it can be interpreted as an SSRF issue. NOTE: a third party has reported that potentially unwanted behavior is caused by misconfiguration of the "Secret chats > Preview links" settingShow less
1Subsonic
1Subsonic
Nov 21, 2024
Dec 19, 2018
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.
1Interspire
1Email Marketer
Nov 21, 2024
Nov 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL. This also allows reading local files with a file:...Show more
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL. This also allows reading local files with a file: URL.Show less
1Mpdf Project
1Mpdf
Nov 21, 2024
Nov 7, 2018
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE:...Show more
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble.Show less
1Tecrail
1Responsive Filemanager
Nov 21, 2024
Oct 31, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
1Typecho
1Typecho
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
1Microsoft
1Exchange Server
Nov 21, 2024
Sep 21, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
1Microsoft
1Active Directory Federation Services
Nov 21, 2024
Sep 18, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.
1Sap
1Hybris
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side imple...Show more
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC.Show less
1Ibm
1Api Connect
Nov 21, 2024
Sep 7, 2018
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a server side request forgery attack. IBM X-Force ID: 148939.
1Seacms
1Seacms
Nov 21, 2024
Sep 4, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
1Gogs
1Gogs
Nov 21, 2024
Sep 3, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
1Icmsdev
1Icms
Nov 21, 2024
Aug 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as demonstra...Show more
An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as demonstrated by 127.0.0.1 in an A record. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-14858.Show less
1Trendmicro
1Control Manager
Nov 21, 2024
Aug 15, 2018
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.
1Sap
1Businessobjects Business Intelligence
Nov 21, 2024
Aug 14, 2018
N/A· v4
9.6 CRITICAL· v3
5.5 MEDIUM· v2
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Re...Show more
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.Show less
1Url Parse Project
1Url Parse
Nov 21, 2024
Aug 12, 2018
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
2Gitea
Gogs
2Gitea
Gogs
Nov 21, 2024
Aug 8, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.