CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,758 vulnerabilities with CWE-918
CVE-2018-1000553 HIGH
Trovebox <= 4.0.0-rc6 - Server-Side Request Forgery via Webhook Component
CVSS 8.8
CVE-2018-12678 CRITICAL
Portainer < 1.18.0 - Unauthenticated Server-Side Request Forgery via Websocket Endpoint
CVSS 9.8
CVE-2018-5752 HIGH
Open-Xchange OX App Suite <7.6.3-7.8.4 - SSRF
CVSS 8.8
CVE-2018-11586 CRITICAL
SearchBlox 8.6.7 - Unauthenticated XML External Entity Injection via REST API Status Endpoint
CVSS 9.8
CVE-2018-1000188 MEDIUM
Jenkins CAS Plugin < 1.4.1 - Server-Side Request Forgery via CasSecurityRealm.java
CVSS 5.4
CVE-2018-1000185 MEDIUM
Jenkins GitHub Branch Source Plugin <2.3.4 - SSRF
CVSS 4.3
CVE-2018-1000184 MEDIUM
Jenkins GitHub Plugin <1.29.0 - SSRF
CVSS 5.4
CVE-2018-1000182 MEDIUM
Jenkins Git Plugin < 3.9.0 - Server-Side Request Forgery via Repository Browser
CVSS 6.4
CVE-2018-9920 MEDIUM
K2 smartforms 4.6.11 - Server-Side Request Forgery via Modified Hostname in Identity STS Forms Scripts URL
CVSS 6.5
CVE-2018-11031 CRITICAL
PHPRAP 1.0.4-1.0.8 - Server-Side Request Forgery via Debug URI
CVSS 9.8
CVE-2018-9919 CRITICAL
Tp-shop 2.0.5-2.0.8 - Server-Side Request Forgery via Backdoor Parameter
CVSS 9.8
CVE-2018-9302 CRITICAL
Cockpit 0.4.4-0.5.5 - Server-Side Request Forgery via URL Parameter
CVSS 9.1
CVE-2018-8939 CRITICAL
WhatsUp Gold < 18.0 - Server-Side Request Forgery via NmAPI.exe
CVSS 9.8
CVE-2018-8801 MEDIUM
GitLab 8.3-10.x - Server-Side Request Forgery in Services and Webhooks
CVSS 6.5
CVE-2018-10174 MEDIUM
Digital Guardian Management Console 7.1.2.0015 - SSRF
CVSS 6.5
CVE-2018-10220 HIGH
Glastopf 3.1.3-dev - Server-Side Request Forgery via abc.php a Parameter
CVSS 8.8
CVE-2018-1000138 CRITICAL
scilico i_librarian < 4.8 - Server-Side Request Forgery via URL Parameter in getFromWeb
CVSS 9.1
CVE-2018-7516 HIGH
Geutebruck G-Cam/EFD-2250 and TopFD-2125 - Server-Side Request Forgery
CVSS 7.3
CVE-2018-1000124 CRITICAL
I Librarian I-librarian <4.8 - XML External Entity (XXE) SSRF
CVSS 10.0
CVE-2018-7667 CRITICAL
Adminer < 4.3.1 - Unauthenticated Server-Side Request Forgery via Server Parameter
CVSS 9.8
CVE-2018-1000067 MEDIUM
Jenkins <2.106-2.89.3 - Info Disclosure
CVSS 5.3
CVE-2018-7055 HIGH
RoomWizard < 4.4.0 - Server-Side Request Forgery via GroupViewProxyServlet URL Parameter
CVSS 7.5
CVE-2018-2370 MEDIUM
SAP BI Launchpad 4.10, 4.20, 4.30 - Server-Side Request Forgery
CVSS 5.3
CVE-2018-1000056 HIGH
Jenkins JUnit Plugin <1.23 - SSRF/DoS
CVSS 8.3
CVE-2018-1000055 HIGH
Jenkins Android Lint Plugin <2.5 - SSRF/DoS
CVSS 8.3
Details
Vulnerabilities 2,758