Vulnerabilities (CVE)

Filtered by CWE-918
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8226 1 Phpbb 1 Phpbb 2020-08-21 5.0 MEDIUM 5.8 MEDIUM
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
CVE-2020-13286 1 Gitlab 1 Gitlab 2020-08-14 4.0 MEDIUM 4.3 MEDIUM
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
CVE-2020-14296 1 Redhat 1 Cloudforms Management Engine 2020-08-12 5.5 MEDIUM 7.1 HIGH
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.
CVE-2020-13295 1 Gitlab 1 Runner 2020-08-12 6.5 MEDIUM 8.8 HIGH
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
CVE-2020-16248 1 Prometheus 1 Blackbox Exporter 2020-08-12 5.0 MEDIUM 5.8 MEDIUM
** DISPUTED ** Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability.
CVE-2020-15823 1 Jetbrains 1 Youtrack 2020-08-10 5.0 MEDIUM 7.5 HIGH
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
CVE-2020-15819 1 Jetbrains 1 Youtrack 2020-08-10 5.0 MEDIUM 5.3 MEDIUM
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
CVE-2019-18394 1 Igniterealtime 1 Openfire 2020-08-07 7.5 HIGH 9.8 CRITICAL
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
CVE-2020-13970 1 Shopware 1 Shopware 2020-07-31 6.5 MEDIUM 8.8 HIGH
Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.
CVE-2020-15879 1 Bitwarden 1 Server 2020-07-24 5.0 MEDIUM 7.5 HIGH
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).
CVE-2020-8205 1 Transloadit 1 Uppy 2020-07-23 5.0 MEDIUM 7.5 HIGH
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
CVE-2020-13788 1 Linuxfoundation 1 Harbor 2020-07-22 4.0 MEDIUM 4.3 MEDIUM
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
CVE-2020-6282 1 Sap 1 Netweaver Application Server Java 2020-07-15 5.0 MEDIUM 5.8 MEDIUM
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.
CVE-2020-14170 1 Atlassian 1 Bitbucket 2020-07-15 4.0 MEDIUM 4.3 MEDIUM
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.
CVE-2019-20408 1 Atlassian 1 Jira 2020-07-08 5.0 MEDIUM 5.3 MEDIUM
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
CVE-2017-5617 2 Debian, Kitfox 2 Debian Linux, Svg Salamander 2020-07-08 5.8 MEDIUM 7.4 HIGH
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
CVE-2020-14056 1 Monstaftp 1 Monsta Ftp 2020-07-08 7.5 HIGH 9.8 CRITICAL
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.
CVE-2020-13484 1 Bitrix24 1 Bitrix24 2020-07-02 7.5 HIGH 9.8 CRITICAL
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
CVE-2020-13650 1 Digdash 1 Digdash 2020-06-24 5.0 MEDIUM 7.5 HIGH
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application credentials. For a request to an internal component, the request is blind, but through the error message it's possible to determine whether the request targeted a open service.
CVE-2019-20872 1 Mattermost 1 Mattermost Server 2020-06-23 2.1 LOW 5.5 MEDIUM
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
CVE-2020-12725 1 Redash 1 Redash 2020-06-22 6.5 MEDIUM 7.2 HIGH
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a lot of flexibility in terms of being able to craft HTTP requests e.g., by adding headers, selecting any HTTP verb, etc.
CVE-2020-9427 1 Open-xchange 1 Ox Guard 2020-06-18 4.0 MEDIUM 5.0 MEDIUM
OX Guard 2.10.3 and earlier allows SSRF.
CVE-2020-8544 1 Open-xchange 1 Open-xchange Appsuite 2020-06-17 4.0 MEDIUM 6.5 MEDIUM
OX App Suite through 7.10.3 allows SSRF.
CVE-2020-4101 1 Hcltech 1 Hcl Digital Experience 2020-06-17 7.5 HIGH 9.8 CRITICAL
"HCL Digital Experience is susceptible to Server Side Request Forgery."
CVE-2020-6275 1 Sap 1 Netweaver As Abap 2020-06-16 6.8 MEDIUM 9.8 CRITICAL
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious server. Furthermore, if NTLM is setup the attacker can compromise confidentiality, integrity and availability of the SAP database.
CVE-2020-9643 1 Adobe 1 Experience Manager 2020-06-15 5.0 MEDIUM 7.5 HIGH
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-9645 1 Adobe 1 Experience Manager 2020-06-15 5.0 MEDIUM 7.5 HIGH
Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-11453 1 Microstrategy 1 Microstrategy Web 2020-06-09 5.0 MEDIUM 5.3 MEDIUM
** DISPUTED ** Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and, while it is not possible to pass parameters in the SSRF request, it is still possible to exploit it to conduct port scanning. An attacker could exploit this vulnerability to enumerate the resources allocated in the network (IP addresses and services exposed). NOTE: MicroStrategy is unable to reproduce the issue reported in any version of its product.
CVE-2020-4529 1 Ibm 1 Maximo Asset Management 2020-06-09 6.5 MEDIUM 7.4 HIGH
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.
CVE-2014-8943 1 Piwigo 1 Lexiglot 2020-06-02 6.5 MEDIUM 8.8 HIGH
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
CVE-2020-13226 1 Wso2 1 Api Manager 2020-05-21 7.5 HIGH 9.8 CRITICAL
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
CVE-2020-4365 5 Hp, Ibm, Linux and 2 more 8 Hp-ux, Aix, I and 5 more 2020-05-15 4.0 MEDIUM 4.3 MEDIUM
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
CVE-2020-5562 1 Cybozu 1 Garoon 2020-05-01 4.0 MEDIUM 4.9 MEDIUM
Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an administrative privilege to issue arbitrary HTTP requests to other web servers via V-CUBE Meeting function.
CVE-2020-10980 1 Gitlab 1 Gitlab 2020-04-09 7.5 HIGH 9.8 CRITICAL
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
CVE-2020-11452 1 Microstrategy 1 Microstrategy Web 2020-04-03 4.0 MEDIUM 4.3 MEDIUM
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the file:// stream wrapper.
CVE-2020-10956 1 Gitlab 1 Gitlab 2020-04-01 7.5 HIGH 9.8 CRITICAL
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
CVE-2017-17697 1 Linuxfoundation 1 Harbor 2020-04-01 5.0 MEDIUM 8.6 HIGH
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
CVE-2020-3769 1 Adobe 1 Experience Manager 2020-03-27 5.0 MEDIUM 7.5 HIGH
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-10791 1 It-novum 1 Openitcockpit 2020-03-27 4.0 MEDIUM 6.5 MEDIUM
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
CVE-2020-8134 1 Ghost 1 Ghost 2020-03-26 5.5 MEDIUM 8.1 HIGH
Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.
CVE-2020-8138 1 Nextcloud 1 Nextcloud Server 2020-03-25 4.0 MEDIUM 6.5 MEDIUM
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
CVE-2019-11574 1 Simplemachines 1 Simple Machine Forum 2020-03-25 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
CVE-2020-8135 1 Uppy 1 Uppy 2020-03-24 7.5 HIGH 9.8 CRITICAL
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
CVE-2020-10077 1 Gitlab 1 Gitlab 2020-03-18 7.5 HIGH 9.8 CRITICAL
GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.
CVE-2019-13121 1 Gitlab 1 Gitlab 2020-03-11 5.0 MEDIUM 7.5 HIGH
An issue was discovered in GitLab Enterprise Edition 10.6 through 12.0.2. The GitHub project integration was vulnerable to an SSRF vulnerability which allowed an attacker to make requests to local network resources. It has Incorrect Access Control.
CVE-2019-12443 1 Gitlab 1 Gitlab 2020-03-10 7.5 HIGH 9.8 CRITICAL
An issue was discovered in GitLab Community and Enterprise Edition 10.2 through 11.11. Multiple features contained Server-Side Request Forgery (SSRF) vulnerabilities caused by an insufficient validation to prevent DNS rebinding attacks.
CVE-2020-10212 1 Tecrail 1 Responsive Filemanager 2020-03-09 7.5 HIGH 9.8 CRITICAL
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.
CVE-2020-7796 1 Synacor 1 Zimbra Collaboration Suite 2020-02-24 6.8 MEDIUM 9.8 CRITICAL
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
CVE-2020-8128 1 Jsreport 1 Jsreport 2020-02-20 7.5 HIGH 9.8 CRITICAL
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
CVE-2017-15943 1 Paloaltonetworks 1 Pan-os 2020-02-17 5.0 MEDIUM 5.3 MEDIUM
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.