Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-11-13 CVE-2017-0889 Server-Side Request Forgery (SSRF) vulnerability in Thoughtbot Paperclip
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class.
network
low complexity
thoughtbot CWE-918
critical
9.8
2017-11-03 CVE-2017-1000139 Server-Side Request Forgery (SSRF) vulnerability in Mahara
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list.
network
low complexity
mahara CWE-918
8.0
2017-10-19 CVE-2017-15644 Server-Side Request Forgery (SSRF) vulnerability in Webmin
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
network
low complexity
webmin CWE-918
8.6
2017-09-29 CVE-2017-7553 Server-Side Request Forgery (SSRF) vulnerability in Redhat Mobile Application Platform 4.0/4.4/4.4.3
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF).
network
low complexity
redhat CWE-918
6.3
2017-09-25 CVE-2017-12905 Server-Side Request Forgery (SSRF) vulnerability in Vebto Pixie - Image Editor 1.4/1.7
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
network
low complexity
vebto CWE-918
critical
10.0
2017-09-08 CVE-2017-12071 Server-Side Request Forgery (SSRF) vulnerability in Synology Photo Station
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.
network
low complexity
synology CWE-918
6.5
2017-09-07 CVE-2017-9458 Server-Side Request Forgery (SSRF) vulnerability in Paloaltonetworks Pan-Os
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via unspecified vectors.
network
low complexity
paloaltonetworks CWE-918
critical
9.8
2017-08-23 CVE-2017-9506 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Oauth
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
network
low complexity
atlassian CWE-918
6.1
2017-08-14 CVE-2017-11149 Server-Side Request Forgery (SSRF) vulnerability in Synology Download Station
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.
network
low complexity
synology CWE-918
6.5
2017-08-11 CVE-2017-11148 Server-Side Request Forgery (SSRF) vulnerability in Synology Chat
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.
network
low complexity
synology CWE-918
6.5