Fallos del tipo CWE-918

3044 resultados

Server-Side Request Forgery (SSRF)

Ocorre quando a aplicação web busca conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Um atacante consegue fazer o servidor requisitar URLs não autorizadas — internas, administrativas ou de terceiros — aproveitando a confiança e as permissões que o servidor possui na rede.

Ejemplo

Um sistema permite gerar thumbnails de imagens externas: o usuário passa uma URL e o servidor faz o download. Um atacante envia 'http://localhost:8080/admin' e consegue acessar painéis administrativos internos que não deveria. Ou envia 'http://169.254.169.254/latest/meta-data' em ambientes AWS e rouba credenciais.

Cómo mitigar

Mantenha uma whitelist rigorosa de domínios e IPs permitidos; bloqueie ranges privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16) e metadados-servers por padrão; valide URLs antes de fazer requisições; use bibliotecas de parsing robustas; considere isolamento de rede para requisições externas.

CVE-2021-34811MEDIUMServer-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote EPSS 0.8%CVE-2023-40017HIGHGeonode Server Side Request Forgery vulnerabilityEPSS 0.8%CVE-2023-6852MEDIUMkalcaddle KodExplorer app.php server-side request forgeryEPSS 0.8%CVE-2022-22993HIGHLimited Server-Side Request Forgery vulnerability on Western Digital My Cloud devices.EPSS 0.8%CVE-2026-45741HIGHGotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixesEPSS 0.8%CVE-2024-12882HIGHSSRF in comfyanonymous/comfyuiEPSS 0.8%CVE-2026-26222CRITICALDocLink .NET Remoting Unauthenticated Arbitrary File Read/Write RCEEPSS 0.8%CVE-2022-4335MEDIUMA blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 whichEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2024-49521HIGHAdobe Commerce | Server-Side Request Forgery (SSRF) (CWE-918)EPSS 0.7%CVE-2024-12376HIGHServer Side Request Forgery in lm-sys/fastchatEPSS 0.7%CVE-2024-12766HIGHSSRF in parisneo/lollms-webuiEPSS 0.7%CVE-2023-1634MEDIUMOTCMS URL Parameter info_deal.php UseCurl server-side request forgeryEPSS 0.7%CVE-2025-34231HIGHVasion Print (formerly PrinterLogic) SSRF via HP badgeSetup.phpEPSS 0.7%CVE-2025-57644CRITICALAccela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative useEPSS 0.7%CVE-2022-28217—Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which alEPSS 0.7%CVE-2022-38212HIGHServer Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS (10.8.1 and 10.7.1 only)EPSS 0.7%CVE-2022-38203HIGHThe allowedProxyHosts property is not fully honored in ArcGIS Enterprise (10.8.1 and 10.7.1 only)EPSS 0.7%CVE-2023-37290HIGHInfoDoc Document On-line Submission and Approval System - Server-Side Request Forgery (SSRF)EPSS 0.7%CVE-2023-3238MEDIUMOTCMS server-side request forgeryEPSS 0.7%