Falhas do tipo CWE-918

3.035 resultados

Falsificação de Solicitação do Lado do Servidor (SSRF)

O servidor web recebe uma URL de um cliente e a recupera sem validar adequadamente o destino, permitindo que um atacante redirecione requisições para hosts internos, serviços privados ou IPs arbitrários. O risco é grave: exposição de dados internos, acesso a serviços administrativos, varredura de rede interna e até execução de código em sistemas conectados.

Exemplo

Uma aplicação oferece um recurso de 'baixar imagem de URL': o usuário envia `https://attacker.com/fetch?url=http://localhost:8080/admin`, e o servidor, sem validar, faz a requisição e retorna o conteúdo da página admin interna ou de um banco de dados local exposto.

Como mitigar

Valide e liste explicitamente domínios/IPs permitidos (whitelist), bloqueie ranges de IPs privados (10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16), use esquemas de URL permitidos (apenas http/https) e desabilite redirects automáticos ou validar o destino final. Considere usar um proxy ou gateway isolado para requisições externas.

CVE-2024-51358CRITICALAn issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new applicationEPSS 1.0%CVE-2022-41495CRITICALClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.EPSS 1.0%CVE-2022-41497CRITICALClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.EPSS 1.0%CVE-2023-41054HIGHLibreY Server-Side Request Forgery (SSRF) vulnerability in image_proxy.phpEPSS 0.9%CVE-2024-51981MEDIUMUnauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Toshiba Tec, and Konica Minolta, Inc.EPSS 0.9%CVE-2021-32698MEDIUMBlind Server-Side Request Forgery (SSRF) in eLabFTWEPSS 0.9%CVE-2023-27162CRITICALopenapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}.EPSS 0.9%CVE-2022-24825MEDIUMSmokescreen SSRF via deny list bypassEPSS 0.9%CVE-2017-6036A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The weEPSS 0.9%CVE-2022-44729Apache XML Graphics Batik: Information disclosure vulnerabilityEPSS 0.9%CVE-2023-23943MEDIUMBlind SSRF via server URL input in the Nextcloud Mail appEPSS 0.9%CVE-2022-0132MEDIUMServer-Side Request Forgery (SSRF) in chocobozzz/peertubeEPSS 0.9%CVE-2022-24739HIGHServer-Side Request Forgery (SSRF) and URL Redirection to Untrusted Site ('Open Redirect') in alltubeEPSS 0.9%CVE-2022-36802MEDIUMThe ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internaEPSS 0.9%CVE-2026-55051MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-32871CRITICALFastMCP OpenAPI Provider has an SSRF & Path Traversal VulnerabilityEPSS 0.9%CVE-2025-55139MEDIUMSSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and IvaEPSS 0.9%CVE-2022-23644HIGHServer-side request forgery in BookWyrmEPSS 0.9%CVE-2026-44492HIGHAxios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)EPSS 0.9%CVE-2023-25262HIGHStimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offersEPSS 0.9%