CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,756 vulnerabilities with CWE-918
CVE-2021-27312 CRITICAL
Gleez CMS 1.2.0 - Server-Side Request Forgery via Request Handler
CVSS 9.4
CVE-2021-35391 HIGH
Deskpro Support Desk <v2021.21.6 - SSRF
CVSS 7.2
CVE-2021-42079 MEDIUM
QuantaStor < 6.0.0.355 - Authenticated Server-Side Request Forgery via Alert Configuration
CVSS 6.2
CVE-2021-36396 HIGH
Moodle - Blind Server-Side Request Forgery via Redirect Handling Bypass
CVSS 7.5
CVE-2021-33926 HIGH
Plone 4.3.2-5.2.4 - Server-Side Request Forgery via RSS Feed Portlet
CVSS 8.8
CVE-2021-43449 HIGH
ONLYOFFICE Server - Server-Side Request Forgery via Document Editor URL Fetch
CVSS 8.1
CVE-2021-37498 MEDIUM
Reprise License Manager < 17.0 - Server-Side Request Forgery via License Activation actserver Parameter
CVSS 6.5
CVE-2021-27693 CRITICAL
PublicCMS < 4.0.202011.b - Server-Side Request Forgery via UEditor Catchimage Action
CVSS 9.8
CVE-2021-43959 MEDIUM
Atlassian Jira Service Management Server & Data Center <4.13.20 - SSRF
CVSS 5.7
CVE-2021-20544 MEDIUM
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, 7.0.2 - Authenticated Server-Side Request Forgery
CVSS 4.3
CVE-2021-20421 MEDIUM
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, 7.0.2 - Authenticated Server-Side Request Forgery
CVSS 4.3
CVE-2021-36761 MEDIUM
Qlik Sense - Server-Side Request Forgery
CVSS 5.3
CVE-2021-41403 CRITICAL
flatCore-CMS 2.0.8 - Server-Side Request Forgery via Dangerous Function Calls
CVSS 9.8
CVE-2021-40604 CRITICAL
IPS Community Suite < 4.6.2 - Authenticated Server-Side Request Forgery via Dynamic Class Name Generation
CVSS 9.1
CVE-2021-40186 MEDIUM
DNN CMS - Server-Side Request Forgery
CVSS 6.5
CVE-2021-40822 HIGH
GeoServer <= 2.18.5 and 2.19.x <= 2.19.2 - Server-Side Request Forgery via Proxy Host Configuration
CVSS 7.5
CVE-2021-36203 MEDIUM
Metasys System Configuration Tool < 14.2.2 - Server-Side Request Forgery
CVSS 5.3
CVE-2021-36202 HIGH
Johnson Controls Metasys <10.1.5, <11.0.2 - SSRF
CVSS 8.4
CVE-2021-33581 HIGH
MashZone NextGen < 10.7 - Server-Side Request Forgery via PPM Connection Availability Check
CVSS 7.2
CVE-2021-44139 HIGH
Sentinel 1.8.2 - Server-Side Request Forgery
CVSS 7.5
CVE-2021-45968 HIGH
Jive XMPP Server - Server-Side Request Forgery via Backend Tomcat Endpoint
CVSS 7.5
CVE-2021-46107 HIGH
Ligeo Archives Ligeo Basics - Server-Side Request Forgery via Download Feature
CVSS 7.5
CVE-2021-45851 HIGH
FUXA 1.1.3 - Server-Side Request Forgery
CVSS 7.5
CVE-2021-39051 MEDIUM
IBM Spectrum Copy Data Management 2.2.0.0-2.2.14.3 - Server-Side Request Forgery via Application Server Registration
CVSS 6.5
CVE-2021-43954 MEDIUM
Atlassian Crucible and Fisheye < 4.8.9 - Server-Side Request Forgery via DefaultRepositoryAdminService
CVSS 4.3
Details
Vulnerabilities 2,756