Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-07-09 CVE-2020-14170 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Bitbucket
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.
network
low complexity
atlassian CWE-918
4.0
2020-07-01 CVE-2020-14056 Server-Side Request Forgery (SSRF) vulnerability in Monstaftp Monsta FTP
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality.
network
low complexity
monstaftp CWE-918
7.5
2020-07-01 CVE-2019-20408 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
5.0
2020-06-24 CVE-2020-13484 Server-Side Request Forgery (SSRF) vulnerability in Bitrix24 20.0.0/20.0.975
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
network
low complexity
bitrix24 CWE-918
7.5
2020-06-19 CVE-2019-20872 Server-Side Request Forgery (SSRF) vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8.
2.1
2020-06-16 CVE-2020-8544 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite 7.8.4
OX App Suite through 7.10.3 allows SSRF.
network
low complexity
open-xchange CWE-918
4.0
2020-06-15 CVE-2020-13650 Server-Side Request Forgery (SSRF) vulnerability in Digdash 2018R2/2019R1/2019R2
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210.
network
low complexity
digdash CWE-918
5.0
2020-06-15 CVE-2020-9427 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange OX Guard 2.10.3
OX Guard 2.10.3 and earlier allows SSRF.
network
low complexity
open-xchange CWE-918
4.0
2020-06-12 CVE-2020-11980 Server-Side Request Forgery (SSRF) vulnerability in Apache Karaf
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files.
network
low complexity
apache CWE-918
6.5
2020-06-12 CVE-2020-9645 Server-Side Request Forgery (SSRF) vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability.
network
low complexity
adobe CWE-918
5.0