CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,756 vulnerabilities with CWE-918
CVE-2022-27311 CRITICAL
Gibbon < 3.4.4 - Server-Side Request Forgery via Crafted URL
CVSS 9.8
CVE-2022-24871 HIGH
Shopware < 6.4.10.1 - Server-Side Request Forgery via Admin SDK
CVSS 7.2
CVE-2022-24862 HIGH
Databasir 1.0.1 - Server-Side Request Forgery via JDBC Driver Download Check
CVSS 7.7
CVE-2022-24825 MEDIUM
stripe/smokescreen < 0.0.3 - Server-Side Request Forgery via Deny List Bypass
CVSS 5.8
CVE-2022-29153 HIGH
HashiCorp Consul <1.9.16-1.11.4 - SSRF
CVSS 7.5
CVE-2022-1037 HIGH
EXMAGE WordPress Plugin < 1.0.7 - Server-Side Request Forgery via Image URL
CVSS 7.2
CVE-2022-27426 HIGH
Chamilo LMS 1.11.0-1.11.15 - Server-Side Request Forgery via Crafted Phar File
CVSS 8.8
CVE-2022-26499 CRITICAL
Asterisk 16.15.0-19.x - Server-Side Request Forgery via STIR/SHAKEN Identity Header
CVSS 9.1
CVE-2022-22339 HIGH
IBM Planning Analytics 2.0 - Authenticated Server-Side Request Forgery
CVSS 7.3
CVE-2022-1213 HIGH
livehelperchat < 3.67 - Server-Side Request Forgery via Port 80/443 Filter Bypass
CVSS 8.1
CVE-2022-1188 LOW
GitLab 12.1-14.7.6, 14.8-14.8.4, 14.9-14.9.1 - Server-Side Request Forgery via Repository Mirroring
CVSS 3.7
CVE-2022-0990 CRITICAL
calibre-web < 0.6.18 - Server-Side Request Forgery
CVSS 9.1
CVE-2022-0939 CRITICAL
calibre-web < 0.6.18 - Server-Side Request Forgery
CVSS 9.9
CVE-2022-0425 MEDIUM
GitLab 7.9-14.7.1 - Server-Side Request Forgery via Irker DNS Rebinding
CVSS 5.4
CVE-2022-1191 HIGH
live_helper_chat < 3.96 - Server-Side Request Forgery via Cobrowse Proxy CSS Endpoint
CVSS 8.1
CVE-2022-27907 MEDIUM
Sonatype Nexus Repository Manager 3.0.0-3.37.0 - Server-Side Request Forgery
CVSS 4.3
CVE-2022-24789 HIGH
C1 CMS < 6.12 - Authenticated Server-Side Request Forgery and Denial of Service
CVSS 7.6
CVE-2022-0249 LOW
GitLab 12.0-14.5.3 - Server-Side Request Forgery via Shared Address Space
CVSS 3.1
CVE-2022-0136 MEDIUM
GitLab 10.5-14.5.4, 14.6-14.6.4, 14.7-14.7.1 - Server-Side Request Forgery via Project Import
CVSS 5.4
CVE-2022-0591 CRITICAL
FormCraft WP <3.8.28 - Server-Side Request Forgery via URL Parameter
CVSS 9.1
CVE-2022-27245 HIGH
MISP < 2.4.156 - Server-Side Request Forgery via generateServerSettings
CVSS 8.8
CVE-2022-0870 MEDIUM
Gogs < 0.12.5 - Server-Side Request Forgery
CVSS 5.3
CVE-2022-24739 HIGH
alltube <3.0.3 - SSRF/Open Redirect
CVSS 7.3
CVE-2022-0767 CRITICAL
janeczku/calibre-web <0.6.17 - SSRF
CVSS 9.9
CVE-2022-0766 CRITICAL
janeczku/calibre-web <0.6.17 - SSRF
CVSS 9.8
Details
Vulnerabilities 2,756