Weaknesses of type CWE-918

3,049 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2023-42439HIGHGeoNode SSRF Bypass to return internal host dataEPSS 1.0%CVE-2023-26492MEDIUMDirectus vulnerable to Server-Side Request Forgery On File ImportEPSS 1.0%CVE-2023-25504MEDIUMApache Superset: Possible SSRF on import datasetsEPSS 1.0%CVE-2022-1191HIGHSSRF on index.php/cobrowse/proxycss/ in livehelperchat/livehelperchatEPSS 1.0%CVE-2023-29292MEDIUMServer Side Request Forgery (SSRF) in FedEx carrier integration configurationEPSS 1.0%CVE-2022-39211LOWServer-Side Request Forgery (SSRF) via potential filter bypass in Nextcloud ServerEPSS 1.0%CVE-2022-41495CRITICALClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.EPSS 1.0%CVE-2022-41496CRITICALiCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.EPSS 1.0%CVE-2024-51358CRITICALAn issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new applicationEPSS 1.0%CVE-2022-41497CRITICALClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.EPSS 1.0%CVE-2023-41054HIGHLibreY Server-Side Request Forgery (SSRF) vulnerability in image_proxy.phpEPSS 0.9%CVE-2026-48331CRITICALAdobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.9%CVE-2026-47938CRITICALAdobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.9%CVE-2024-51981MEDIUMUnauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Toshiba Tec, and Konica Minolta, Inc.EPSS 0.9%CVE-2026-70324HIGHMicrosoft SharePoint Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2021-32698MEDIUMBlind Server-Side Request Forgery (SSRF) in eLabFTWEPSS 0.9%CVE-2026-65813MEDIUMMicrosoft Exchange Server Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-27162CRITICALopenapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}.EPSS 0.9%CVE-2022-24825MEDIUMSmokescreen SSRF via deny list bypassEPSS 0.9%CVE-2017-6036—A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The weEPSS 0.9%