Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-7616 Server-Side Request Forgery (SSRF) vulnerability in Elastic Kibana
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer.
network
low complexity
elastic CWE-918
4.9
2019-07-10 CVE-2018-19571 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.
network
low complexity
gitlab CWE-918
7.7
2019-07-10 CVE-2018-19495 Server-Side Request Forgery (SSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1.
network
low complexity
gitlab CWE-918
6.5
2019-07-03 CVE-2019-9827 Server-Side Request Forgery (SSRF) vulnerability in Hawt Hawtio
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
network
low complexity
hawt CWE-918
critical
9.8
2019-07-03 CVE-2019-12852 Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Youtrack
An SSRF attack was possible on a JetBrains YouTrack server.
network
low complexity
jetbrains CWE-918
critical
9.8
2019-06-11 CVE-2019-12153 Server-Side Request Forgery (SSRF) vulnerability in Realobjects Pdfreactor
Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
network
low complexity
realobjects CWE-918
critical
10.0
2019-06-05 CVE-2019-9187 Server-Side Request Forgery (SSRF) vulnerability in Ikiwiki
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin.
network
low complexity
ikiwiki CWE-918
7.5
2019-06-05 CVE-2019-1872 Server-Side Request Forgery (SSRF) vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests.
network
low complexity
cisco CWE-918
5.3
2019-05-29 CVE-2019-6981 Server-Side Request Forgery (SSRF) vulnerability in Synacor Zimbra Collaboration Suite
Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.
network
low complexity
synacor CWE-918
6.5
2019-05-28 CVE-2018-17198 Server-Side Request Forgery (SSRF) vulnerability in Apache Roller
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability.
network
low complexity
apache CWE-918
critical
9.8