CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,740 vulnerabilities with CWE-918
CVE-2024-34580 MEDIUM
Apache XML Security for C++ <2.0.4 - SSRF
CVSS 5.3
CVE-2024-29173 MEDIUM
Dell PowerProtect DD < 7.13 - Server-Side Request Forgery
CVSS 6.8
CVE-2024-5015 HIGH
WhatsUp Gold < 23.1.3 - Authenticated Server-Side Request Forgery in SessionController
CVSS 7.1
CVE-2024-5014 HIGH
WhatsUp Gold < 23.1.3 - Authenticated Server-Side Request Forgery via GetASPReport Feature
CVSS 7.1
CVE-2024-5746 HIGH
GitHub Enterprise Server < 3.9.16 - Authenticated Remote Code Execution via SSRF
CVSS 7.6
CVE-2024-37818 HIGH
strapi.io Image Proxy - Server-Side Request Forgery
CVSS 8.6
CVE-2024-5021 CRITICAL
WordPress Picture/Portfolio/Media Gallery <3.0.1 - SSRF
CVSS 9.3
CVE-2024-4404 HIGH
ElementsKit PRO <= 3.6.2 - Authenticated Server-Side Request Forgery via render_raw Function
CVSS 8.5
CVE-2024-37164 HIGH
CVAT 2.1.0-2.14.3 - Server-Side Request Forgery via Cloud Storage Endpoint URL
CVSS 7.1
CVE-2024-34111 MEDIUM
Adobe Commerce 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier - Authenticated Server-Side Request Forgery
CVSS 6.5
CVE-2024-36471 HIGH
Apache Allura 1.0.1-1.16.0 - Server-Side Request Forgery via Import Functionality
CVSS 7.5
CVE-2024-36414 HIGH
SuiteCRM < 7.14.4 - Server-Side Request Forgery via Connectors File Verification
CVSS 7.7
CVE-2024-4354 MEDIUM
TablePress <= 2.3 - Authenticated Server-Side Request Forgery via get_files_to_import()
CVSS 6.4
CVE-2024-5328 CRITICAL
lunary - Server-Side Request Forgery via SAML IDP XML Download Endpoint
CVSS 9.3
CVE-2024-5186 HIGH
privategpt 0.5.0 - Server-Side Request Forgery via File Upload Path Parameter
CVSS 7.2
CVE-2024-4851 HIGH
Quivr 0.0.204 - Server-Side Request Forgery via Crawl URL Parameter
CVSS 7.7
CVE-2024-3149 HIGH
AnythingLLM Upload Link - Manager Server-Side Request Forgery
CVSS 8.8
CVE-2024-3095 HIGH
langchain 0.1.5-<0.2.9 - Server-Side Request Forgery via Web Research Retriever
CVSS 7.7
CVE-2024-5482 CRITICAL
lollms_web_ui - Server-Side Request Forgery via add_webpage Endpoint
CVSS 9.8
CVE-2024-4325 HIGH
gradio < 4.41.0 - Server-Side Request Forgery via /queue/join Endpoint
CVSS 8.6
CVE-2024-3152 HIGH
mintplex-labs/anything-llm - Privilege Escalation, SSRF
CVSS 8.8
CVE-2024-4177 HIGH
Bitdefender GravityZone < 6.38.1-2 - Server-Side Request Forgery via Host Whitelist Parser
CVSS 8.1
CVE-2024-20404 HIGH
Cisco Finesse - Unauthenticated Server-Side Request Forgery
CVSS 7.2
CVE-2024-5526 HIGH
Grafana OnCall 1.1.37-1.5.1 - Server-Side Request Forgery via Webhook Functionality
CVSS 7.7
CVE-2024-4084 HIGH
AnythingLLM URL Validation Bypass - Server-Side Request Forgery
CVSS 7.5
Details
Vulnerabilities 2,740