CWE-918— Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.— MITRE CWE catalog
3,315 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-918page 2 of 67
- CVE-2017-16865MEDIUMCVSS 5.3EG 5.32018-01-17
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw mayb…
- CVE-2017-16870HIGHCVSS 8.1EG 8.12017-11-17
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary
- CVE-2017-17674CRITICALCVSS 9.8EG 9.82021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side …
- CVE-2017-17697HIGHCVSS 8.6EG 8.62017-12-15
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
- CVE-2017-18036MEDIUMCVSS 4.3EG 4.32018-02-02
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Request Forgery (SSRF) vulnerability.
- CVE-2017-18096HIGHCVSS 7.2EG 7.22018-04-04
The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources …
- CVE-2017-18638HIGHCVSS 7.5EG 7.52019-10-11
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to thi…
- CVE-2017-20106MEDIUMCVSS 5.3EG 5.32022-06-28
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-si…
- CVE-2017-20157MEDIUMCVSS 5.5EG 5.52022-12-31
A vulnerability was found in Ariadne Component Library up to 2.x. It has been classified as critical. Affected is an unknown function of the file src/url/Url.php. The manipulation leads to server-side request forgery. Upgrading to version …
- CVE-2017-3164HIGHCVSS 7.5EG 7.52019-03-08
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET…
- CVE-2017-3546MEDIUMCVSS 6.5EG 6.52017-04-24
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauth…
- CVE-2017-4928HIGHCVSS 7.5EG 7.52017-11-17
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these i…
- CVE-2017-5518HIGHCVSS 7.4EG 7.42017-01-17
The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.
- CVE-2017-5617HIGHCVSS 7.4EG 7.42017-03-16
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
- CVE-2017-5643HIGHCVSS 7.4EG 7.42017-03-16
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
- CVE-2017-6036MEDIUMCVSS 6.5EG 6.52017-06-30
A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server receives a request, but does not sufficiently verify that the request is being sent to the…
- CVE-2017-6130HIGHCVSS 7.4EG 7.42017-04-06
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.
- CVE-2017-6201HIGHCVSS 8.1EG 8.12018-02-06
A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as firewalls that prevent the a…
- CVE-2017-7200MEDIUMCVSS 5.8EG 5.82017-03-21
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http…
- CVE-2017-7272HIGHCVSS 7.4EG 7.42017-03-27
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port n…
- CVE-2017-7553MEDIUMCVSS 6.3EG 6.32017-09-29
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
- CVE-2017-7566HIGHCVSS 7.7EG 7.72017-04-06
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
- CVE-2017-7569HIGHCVSS 8.6EG 8.62017-04-06
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
- CVE-2017-8794CRITICALCVSS 10.0EG 10.02017-05-05
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///e…
- CVE-2017-9066HIGHCVSS 8.6EG 8.62017-05-18
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
- CVE-2017-9307MEDIUMCVSS 6.5EG 6.52017-05-31
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.
- CVE-2017-9355HIGHCVSS 7.4EG 7.42017-06-07
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.
- CVE-2017-9458CRITICALCVSS 9.8EG 9.82017-09-07
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to ob…
- CVE-2017-9506HIGHCVSS 6.1EG 8.32017-08-23
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack …
- CVE-2018-0398CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.
- CVE-2018-0399CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a cleartext password from an affected system. Cisco Bug IDs: CSCvg71044.
- CVE-2018-0403CRITICALCVSS 9.8EG 9.82018-07-18
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.
- CVE-2018-1000054HIGHCVSS 8.3EG 8.32018-02-09
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request…
- CVE-2018-1000055HIGHCVSS 8.3EG 8.32018-02-09
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-sid…
- CVE-2018-1000056HIGHCVSS 8.3EG 8.32018-02-09
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side requ…
- CVE-2018-1000067MEDIUMCVSS 5.3EG 5.32018-02-16
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
- CVE-2018-1000124CRITICALCVSS 10.0EG 10.02018-03-13
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack…
- CVE-2018-1000138CRITICALCVSS 9.1EG 9.12018-03-23
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.
- CVE-2018-1000182MEDIUMCVSS 6.4EG 6.42018-06-05
A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrowser.java, ViewGitWeb.java that allows attackers with Overall…
- CVE-2018-1000184MEDIUMCVSS 5.4EG 5.42018-06-05
A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-1000185MEDIUMCVSS 4.3EG 4.32018-06-05
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-1000188MEDIUMCVSS 5.4EG 5.42018-06-05
A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-1000421MEDIUMCVSS 6.5EG 6.52019-01-09
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-s…
- CVE-2018-1000422MEDIUMCVSS 6.5EG 6.52019-01-09
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server w…
- CVE-2018-1000553HIGHCVSS 8.8EG 8.82018-06-26
Trovebox version <= 4.0.0-rc6 contains a Server-Side request forgery vulnerability in webhook component that can result in read or update internal resources. This attack appear to be exploitable via HTTP request. This vulnerability appears…
- CVE-2018-1000606MEDIUMCVSS 6.5EG 6.52018-06-26
A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
- CVE-2018-10174MEDIUMCVSS 6.5EG 6.52018-04-20
Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user h…
- CVE-2018-10220HIGHCVSS 8.8EG 8.82018-04-19
Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/handlers/emulators/rfi.py supports Remote …
- CVE-2018-1042MEDIUMCVSS 6.5EG 6.52018-01-22
Moodle 3.x has Server Side Request Forgery in the filepicker.
- CVE-2018-10511CRITICALCVSS 10.0EG 10.02018-08-15
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.
Map vulnerabilities like CWE-918 to your infrastructure
EchelonGraph correlates every CVE — across CWE-918 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →