CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,740 vulnerabilities with CWE-918
CVE-2024-48234 MEDIUM
mipjz 5.0.5 - Server-Side Request Forgery via PostAddress Parameter
CVSS 4.9
CVE-2024-48232 MEDIUM
Mipjz 5.0.5 mipPost postAddress - Server-Side Request Forgery File Read
CVSS 4.9
CVE-2024-48450 MEDIUM
Huly Platform 0.6.295 - Arbitrary File Upload and Remote Code Execution via Crafted HTML File
CVSS 6.5
CVE-2024-47883 CRITICAL
OpenRefine Butterfly < 1.2.6 - Path Traversal and Server-Side Request Forgery via file:/ URL
CVSS 9.1
CVE-2024-45518 HIGH
Zimbra Collaboration <10.1.1-8.8.15 - SSRF
CVSS 8.8
CVE-2024-49312 MEDIUM
Edwiser Bridge <= 3.0.7 - Server-Side Request Forgery
CVSS 4.9
CVE-2024-46468 HIGH
jpress <= 5.1.1 - Server-Side Request Forgery
CVSS 7.5
CVE-2024-47830 CRITICAL
plane < 0.23.0 - Server-Side Request Forgery via Image Hostname Wildcard
CVSS 9.3
CVE-2024-45317 HIGH
SonicWall SMA1000 <= 12.4.3-02676 - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2024-47167 CRITICAL
Gradio < 5.0 queue/join - Server-Side Request Forgery
CVSS 9.8
CVE-2024-8977 HIGH
GitLab 15.10-17.2.8, 17.3-17.3.4, 17.4-17.4.1 - Server-Side Request Forgery via Product Analytics Dashboard
CVSS 8.2
CVE-2024-45119 MEDIUM
Adobe Commerce 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier - Authenticated Server-Side Request Forgery
CVSS 4.9
CVE-2024-47008 HIGH
Ivanti Avalanche < 6.4.5 - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2024-45291 MEDIUM
PhpSpreadsheet Image Embedding - File Read and Server-Side Request Forgery
CVSS 6.3
CVE-2024-45290 HIGH
PHPSpreadsheet <1.29.2, >=2.2.0 <2.3.0 - Absolute Path Traversal via Crafted XLSX File
CVSS 7.7
CVE-2024-9410 MEDIUM
Ada.cx Sentry Data Scraping Endpoint - Blind Server-Side Request Forgery
CVSS 5.3
CVE-2024-45843 LOW
Mattermost 9.5.0-9.5.8 - Server-Side Request Forgery via Oracle Cloud and Alibaba Metadata Endpoints
CVSS 3.1
CVE-2024-47222 CRITICAL
New Cloud MyOffice SDK Collaborative Editing Server <2.9 - SSRF
CVSS 9.8
CVE-2024-40441 MEDIUM
Doccano <v1.8.4, v0.1.23 - Privilege Escalation
CVSS 6.6
CVE-2024-47066 CRITICAL
lobehub/lobe_chat < 1.19.13 - Server-Side Request Forgery via Redirect Bypass
CVSS 9.0
CVE-2024-43989 HIGH
Firsh Justified Image Grid <4.6.1 - SSRF
CVSS 7.5
CVE-2024-46990 MEDIUM
Directus < 10.13.3 - Improper Access Control via Loopback Device Bypass
CVSS 5.0
CVE-2024-38183 CRITICAL
GroupMe - Unauthenticated Privilege Escalation
CVSS 9.8
CVE-2024-47049 HIGH
czim/file-handling <1.5.0, <2.3.0 - SSRF & Path Traversal
CVSS 8.2
CVE-2024-6587 HIGH
litellm 1.38.10 - Server-Side Request Forgery via api_base Parameter
CVSS 7.5
Details
Vulnerabilities 2,740