Weaknesses of type CWE-918

3,049 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2022-0508MEDIUMServer-Side Request Forgery (SSRF) in chocobozzz/peertubeEPSS 0.9%CVE-2023-24495MEDIUMA Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. EPSS 0.9%CVE-2026-77987CRITICALGitHub Enterprise Server notebook viewer vulnerable to Server-side request forgeryEPSS 0.9%CVE-2023-26735HIGHblackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to dEPSS 0.9%CVE-2023-6849HIGHkalcaddle kodbox app.php cover server-side request forgeryEPSS 0.9%CVE-2024-47578CRITICALMultiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)EPSS 0.9%CVE-2024-29090MEDIUMWordPress AI Engine plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.9%CVE-2025-27651CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: ElatecEPSS 0.9%CVE-2024-45119MEDIUMAdobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.9%CVE-2017-18036—The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they couEPSS 0.9%CVE-2025-27655CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: CPA v1EPSS 0.9%CVE-2025-27652CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: rfIDEAEPSS 0.9%CVE-2023-46295CRITICALAn issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exEPSS 0.9%CVE-2024-0510HIGHHaoKeKeJi YiQiNiu Api.php http_post server-side request forgeryEPSS 0.9%CVE-2022-44730—Apache XML Graphics Batik: Information disclosure vulnerabilityEPSS 0.9%CVE-2022-38211HIGHServer Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.9.1, 10.8.1 and 10.7.1 only)EPSS 0.9%CVE-2026-57993HIGHMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.9%CVE-2021-23029—On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-SideEPSS 0.9%CVE-2026-58612HIGHPowerShell Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-62902MEDIUM.NET Information Disclosure VulnerabilityEPSS 0.9%