CWE-918

Server-Side Request Forgery (SSRF)

Parent: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

2,758 vulnerabilities with CWE-918
CVE-2021-20347 MEDIUM
IBM Engineering Lifecycle Management - Authenticated Server-Side Request Forgery
CVSS 5.4
CVE-2021-20346 MEDIUM
IBM Jazz Foundation & IBM Engineering - SSRF
CVSS 5.4
CVE-2021-20345 MEDIUM
IBM Jazz Foundation & IBM Engineering - SSRF
CVSS 5.4
CVE-2021-20343 MEDIUM
IBM Jazz Foundation/Engineering - SSRF
CVSS 5.4
CVE-2021-33184 HIGH
Synology Download Station <3.8.15-3563 - SSRF
CVSS 7.7
CVE-2021-33181 MEDIUM
Synology Video Station <2.4.10-1632 - SSRF
CVSS 6.6
CVE-2021-25640 MEDIUM
Apache Dubbo 2.5.0-2.6.8 and 2.7.0-2.7.9 - Server-Side Request Forgery via parseURL Host Check Bypass
CVSS 6.1
CVE-2021-21985 CRITICAL KEV
VMware vCenter Server - Remote Code Execution via Virtual SAN Health Check Plugin
CVSS 9.8
CVE-2021-30108 CRITICAL
Feehi CMS 2.1.1 - Server-Side Request Forgery via HTTP Referer Header
CVSS 9.1
CVE-2021-33511 HIGH
Plone < 5.2.4 - Server-Side Request Forgery via lxml Parser
CVSS 7.5
CVE-2021-33510 MEDIUM
Plone < 5.2.4 - Authenticated Server-Side Request Forgery via Event iCal URL
CVSS 4.3
CVE-2021-20535 MEDIUM
IBM Jazz Reporting Service <7.0.2 - SSRF
CVSS 5.4
CVE-2021-31910 HIGH
JetBrains TeamCity < 2020.2.3 - Server-Side Request Forgery
CVSS 7.5
CVE-2021-31828 HIGH
Amazon Open Distro for Elasticsearch < 1.13.1.0 - Authenticated Server-Side Request Forgery via Alerting Plugin
CVSS 7.1
CVE-2021-29490 MEDIUM
jellyfin < 10.7.3 - Unauthenticated Server-Side Request Forgery via imageUrl Parameter
CVSS 5.8
CVE-2021-29145 CRITICAL
Aruba ClearPass 6.7.0-6.7.14 - Server-Side Request Forgery
CVSS 9.8
CVE-2021-31779 MEDIUM
Yoast SEO < 7.2.1 - Authenticated Server-Side Request Forgery
CVSS 6.4
CVE-2021-29475 CRITICAL
HedgeDoc < 1.5.0 - Server-Side Request Forgery via PDF Export
CVSS 10.0
CVE-2021-29431 HIGH
Sydent < 2.3.0 - Server-Side Request Forgery via HTTP GET Request
CVSS 7.7
CVE-2021-28060 MEDIUM
Group Office 6.4.196 - Server-Side Request Forgery via URL Parameter
CVSS 5.3
CVE-2021-27905 CRITICAL
Apache Solr < 8.8.2 - Server-Side Request Forgery via ReplicationHandler masterUrl Parameter
CVSS 9.8
CVE-2021-29357 HIGH
OutSystems Platform Server SSRF via ECT Provider (10 < 10.0.1104.0, 11 < 11.9.0, LifeTime < 11.7.0)
CVSS 8.6
CVE-2021-20480 MEDIUM
IBM WebSphere Application Server <8.6 - SSRF
CVSS 6.5
CVE-2021-24150 HIGH
LikeBtn WordPress Like Button < 2.6.32 - Unauthenticated Server-Side Request Forgery
CVSS 7.5
CVE-2021-28941 MEDIUM
MagpieRSS 0.72 - Server-Side Request Forgery via Snoopy curl Request
CVSS 5.3
Details
Vulnerabilities 2,758