CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,748 vulnerabilities with CWE-918
CVE-2023-26366 MEDIUM
Adobe Commerce <=2.4.7-beta1, <=2.4.6-p2, <=2.4.5-p4, <=2.4.4-p5 - SSRF
CVSS 6.8
CVE-2023-41763 MEDIUM KEV
Skype for Business Server - Server-Side Request Forgery
CVSS 5.3
CVE-2023-42477 MEDIUM
SAP NetWeaver AS Java 7.50 - Server-Side Request Forgery in GRMG Heartbeat Application
CVSS 6.5
CVE-2023-39854 MEDIUM
ATX Ucrypt < 3.5 - Authenticated Server-Side Request Forgery via /hydra/view/get_cc_url Parameter
CVSS 6.5
CVE-2023-44384 MEDIUM
discourse_jira < 2023-10-01 - Authenticated Server-Side Request Forgery via Jira URL Configuration
CVSS 4.1
CVE-2023-3744 CRITICAL
SLims 9.6.0 - Authenticated Server-Side Request Forgery via scrape_image.php imageURL Parameter
CVSS 9.9
CVE-2023-44469 MEDIUM
LemonLDAP::NG < 2.17.1 - Authenticated Server-Side Request Forgery via OpenID Connect request_uri Parameter
CVSS 4.3
CVE-2023-43654 CRITICAL
TorchServe 0.1.0-0.8.1 - Server-Side Request Forgery via Model URL Parameter
CVSS 10.0
CVE-2023-41449 CRITICAL
phpkobo AjaxNewsTicker 1.0.5 - Remote Code Execution via reque Parameter
CVSS 9.8
CVE-2023-42812 MEDIUM
Galaxy < 22.05 - Server-Side Request Forgery via URI Handling
CVSS 6.3
CVE-2023-42450 MEDIUM
Mastodon 4.2.0-beta1 to 4.2.0-rc1 - HTTP Request Injection
CVSS 5.4
CVE-2023-3025 HIGH
Dropbox Folder Share plugin for WordPress <=1.9.7 - SSRF
CVSS 7.2
CVE-2023-42439 HIGH
GeoNode 3.2.0-4.1.3 - Server-Side Request Forgery via Whitelist Bypass
CVSS 7.5
CVE-2023-42398 CRITICAL
zzCMS 2023 - Code Execution and Information Disclosure via ueditor
CVSS 9.8
CVE-2023-4893 MEDIUM
Crayon Syntax Highlighter <2.8.4 - SSRF
CVSS 6.4
CVE-2023-4878 MEDIUM
InstantCMS < 2.16.1-git - Server-Side Request Forgery
CVSS 5.4
CVE-2023-41327 MEDIUM
WireMock Studio < 2.32.0-17 - Server-Side Request Forgery via Webhooks Configuration
CVSS 4.6
CVE-2023-39967 CRITICAL
WireMock Studio < 2.32.0-17 - Server-Side Request Forgery via TestRequester, Webhooks, or Proxy Mode
CVSS 10.0
CVE-2023-41937 HIGH
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0-2.8.3 - Server-Side Request Forgery via Webhook Payload
CVSS 7.5
CVE-2023-36388 MEDIUM
Apache Superset <= 2.1.0 - Authenticated Server-Side Request Forgery via Network Connection Test
CVSS 4.3
CVE-2023-41055 HIGH
LibreY <commit be59098abd119cda70b15bf3faac596dfd39a744 - SSRF
CVSS 7.5
CVE-2023-41054 HIGH
LibreY <8f9b9803f231e2954e5b49987a532d28fe50a627 - SSRF
CVSS 8.2
CVE-2023-36088 HIGH
NebulaGraph Studio 3.7.0 - Server-Side Request Forgery
CVSS 7.5
CVE-2023-40969 MEDIUM
Senayan Library Management Systems SLIMS 9 Bulian <9.6.1 - SSRF
CVSS 6.1
CVE-2023-4651 MEDIUM
instantcms < 2.16.1 - Server-Side Request Forgery
CVSS 5.4
Details
Vulnerabilities 2,748