CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,750 vulnerabilities with CWE-918
CVE-2022-41477 CRITICAL
WeBid <=1.2.2 - Server-Side Request Forgery via Theme Parameter
CVSS 9.1
CVE-2022-36802 MEDIUM
Atlassian Jira Align < 10.109.2 - Server-Side Request Forgery via ManageJiraConnectors API
CVSS 4.9
CVE-2022-41497 CRITICAL
ClipperCMS 1.3.3 - Server-Side Request Forgery via pkg_url Parameter
CVSS 9.8
CVE-2022-41496 CRITICAL
iCMS v7.0.16 - Server-Side Request Forgery via URL Parameter
CVSS 9.8
CVE-2022-41495 CRITICAL
ClipperCMS 1.3.3 - Server-Side Request Forgery via RSS URL News Parameter
CVSS 9.8
CVE-2022-36551 MEDIUM
Heartex - Label Studio Community Edition <1.5.0 - SSRF
CVSS 6.5
CVE-2022-41040 HIGH KEV
Microsoft Exchange ProxyNotShell RCE
CVSS 8.8
CVE-2022-35282 MEDIUM
IBM WebSphere Application Server 7.0.0.0-7.0.0.44 - Server-Side Request Forgery
CVSS 6.5
CVE-2022-2352 HIGH
Post SMTP Mailer/Email Log <2.1.7 - SSRF
CVSS 7.2
CVE-2022-23464 MEDIUM
Nepxion Discovery < 6.16.2 - Server-Side Request Forgery via RouterResourceImpl
CVSS 4.3
CVE-2022-39239 MEDIUM
nuxtjs/netlify-ipx < 1.2.3 - Server-Side Request Forgery via Header Injection
CVSS 6.1
CVE-2022-40146 HIGH
Apache Batik 1.14 - Server-Side Request Forgery via Jar URL
CVSS 7.5
CVE-2022-38648 MEDIUM
Apache XML Graphics Batik 1.14 - SSRF
CVSS 5.3
CVE-2022-38398 MEDIUM
Apache XML Graphics Batik <1.14 - SSRF
CVSS 5.3
CVE-2022-40357 CRITICAL
Z-BlogPHP <= 1.7.2 - Server-Side Request Forgery via UEditor Crawler Source Parameter
CVSS 9.8
CVE-2022-38931 HIGH
BaijiaCMS V4 4.1.4 - Server-Side Request Forgery via url Parameter
CVSS 8.8
CVE-2022-30579 HIGH
TIBCO Spotfire Analytics Platform and Spotfire Server 12.0.0 - Server-Side Request Forgery in Web Player
CVSS 7.1
CVE-2022-39211 LOW
Nextcloud Server < 23.0.8 and Nextcloud Enterprise Server < 22.2.10.4 - Server-Side Request Forgery
CVSS 3.0
CVE-2022-2912 MEDIUM
Craw Data < 1.0.0 - Authenticated Server-Side Request Forgery via URL Parameter
CVSS 4.3
CVE-2022-36112 LOW
GLPI < 10.0.3 - Server-Side Request Forgery via RSS Feed or External Calendar
CVSS 3.5
CVE-2022-2900 CRITICAL
parse-url < 8.1.0 - Server-Side Request Forgery
CVSS 9.1
CVE-2022-38298 HIGH
Appsmith v1.7.11 - Authenticated Server-Side Request Forgery via AWS Metadata Endpoint
CVSS 8.8
CVE-2022-38292 CRITICAL
SLiMS Senayan Library Management System <9.4.2 - SSRF
CVSS 9.8
CVE-2022-36376 MEDIUM
Rank Math SEO <= 1.0.95 - Server-Side Request Forgery
CVSS 6.8
CVE-2022-40305 CRITICAL
Canto Cumulus < 11.1.3 - Server-Side Request Forgery via Login Form Server Parameter
CVSS 9.8
Details
Vulnerabilities 2,750