Fallos del tipo CWE-918

3049 resultados

Server-Side Request Forgery (SSRF)

Ocorre quando a aplicação web busca conteúdo de uma URL fornecida pelo usuário sem validar adequadamente o destino. Um atacante consegue fazer o servidor requisitar URLs não autorizadas — internas, administrativas ou de terceiros — aproveitando a confiança e as permissões que o servidor possui na rede.

Ejemplo

Um sistema permite gerar thumbnails de imagens externas: o usuário passa uma URL e o servidor faz o download. Um atacante envia 'http://localhost:8080/admin' e consegue acessar painéis administrativos internos que não deveria. Ou envia 'http://169.254.169.254/latest/meta-data' em ambientes AWS e rouba credenciais.

Cómo mitigar

Mantenha uma whitelist rigorosa de domínios e IPs permitidos; bloqueie ranges privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16) e metadados-servers por padrão; valide URLs antes de fazer requisições; use bibliotecas de parsing robustas; considere isolamento de rede para requisições externas.

CVE-2022-47635CRITICALWildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZEPSS 0.6%CVE-2024-0946HIGH60IndexPage Parameter index.php server-side request forgeryEPSS 0.6%CVE-2026-40242HIGHArcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch EndpointEPSS 0.6%CVE-2025-37090MEDIUMA server-side request forgery vulnerability exists in HPE StoreOnce Software.EPSS 0.6%CVE-2022-37938CRITICALUnauthenticated server side request forgery in HPE Serviceguard ManagerEPSS 0.6%CVE-2024-0945HIGH60IndexPage Parameter file.php server-side request forgeryEPSS 0.6%CVE-2025-3954MEDIUMChurchCRM Referer server-side request forgeryEPSS 0.6%CVE-2024-48944MEDIUMApache Kylin: SSRF vulnerability in the diagnosis apiEPSS 0.6%CVE-2026-35037HIGHEch0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadataEPSS 0.6%CVE-2022-42894HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulEPSS 0.6%CVE-2022-36451HIGHA vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conductEPSS 0.6%CVE-2024-44721CRITICALSeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.EPSS 0.6%CVE-2024-22648MEDIUMA Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attaEPSS 0.6%CVE-2023-34959MEDIUMAn issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the seEPSS 0.6%CVE-2023-47619HIGHAudiobookshelf Server-Side Request Forgery and Arbitrary File Read VulnerabilityEPSS 0.6%CVE-2023-1895HIGHGetwid – Gutenberg Blocks <= 1.8.3 - Authenticated(Subscriber+) Server Side Request ForgeryEPSS 0.6%CVE-2026-15330MEDIUMzhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgeryEPSS 0.6%CVE-2023-6570HIGHServer-Side Request Forgery (SSRF) in kubeflow/kubeflowEPSS 0.6%CVE-2025-34021HIGHSelea Targa IP OCR-ANPR Camera Server-Side Request ForgeryEPSS 0.6%CVE-2026-15927MEDIUMQuay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validationEPSS 0.6%