Weaknesses of type CWE-918

3,050 results

Falsificação de Solicitação no Servidor (SSRF)

O servidor web recupera conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Isso permite que um atacante force o servidor a fazer requisições para hosts internos, serviços privados ou sistemas que não deveriam ser acessíveis, contornando controles de rede e autenticação.

Example

Uma aplicação oferece um proxy de imagens: recebe a URL 'http://exemplo.com/foto.jpg' e retorna o conteúdo. Um atacante envia 'http://localhost:8080/admin' ou 'http://192.168.1.100/dados-internos', forçando o servidor a acessar sistemas internos e exfiltrar dados sensíveis.

How to mitigate

Valide e faça whitelist de domínios/IPs permitidos antes de fazer a requisição; rejeite URLs locais, privadas (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) e metadados (169.254.169.254); use DNS pinning e resoluções contínuas. Em clouds, restrinja acesso ao serviço de metadados via iptables ou IMDSv2.

CVE-2022-28217—Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which alEPSS 0.7%CVE-2022-38203HIGHThe allowedProxyHosts property is not fully honored in ArcGIS Enterprise (10.8.1 and 10.7.1 only)EPSS 0.7%CVE-2023-37290HIGHInfoDoc Document On-line Submission and Approval System - Server-Side Request Forgery (SSRF)EPSS 0.7%CVE-2022-38212HIGHServer Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)EPSS 0.7%CVE-2023-3238MEDIUMOTCMS server-side request forgeryEPSS 0.7%CVE-2024-31979HIGHApache StreamPipes: Possibility of SSRF in pipeline element installation processEPSS 0.7%CVE-2018-17452CRITICALAn issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is SEPSS 0.7%CVE-2024-53705HIGHA Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection tEPSS 0.7%CVE-2023-47116MEDIUMLabel Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` ProtectionsEPSS 0.7%CVE-2026-32210CRITICALMicrosoft Dynamics 365 (online) Spoofing VulnerabilityEPSS 0.7%CVE-2023-3958HIGHWP Remote Users Sync <= 1.2.12 - Authenticated (Subscriber+) Server Side Request ForgeryEPSS 0.7%CVE-2026-16268HIGHNewsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce HandlerEPSS 0.7%CVE-2026-85666HIGHogx 1.3.1 Server-Side Request Forgery via MCP tool server_urlEPSS 0.7%CVE-2022-23464MEDIUMPotential Server Side Request Forgery (SSRF) in Nepxion DiscoveryEPSS 0.7%CVE-2023-26366MEDIUMValidate Your Inputs | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.7%CVE-2026-82000CRITICALAdobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.7%CVE-2024-8955MEDIUMSSRF in composiohq/composioEPSS 0.7%CVE-2026-50112HIGHApache CloudStack: RCE and SSRF in direct download, metalink and NFS templatesEPSS 0.7%CVE-2023-27586CRITICALCairoSVG improperly processes SVG files loaded from external resourcesEPSS 0.7%CVE-2026-49328MEDIUMApache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRFEPSS 0.7%