Show filters
121 Total Results
Displaying 1-10 of 121
Sort by:
Attacker Value
Very High
CVE-2020-13379
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.
4
Attacker Value
Very High
CVE-2020-8135
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
0
Attacker Value
Unknown
CVE-2020-28735
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
0
Attacker Value
Unknown
CVE-2020-35850
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
0
Attacker Value
Unknown
CVE-2020-26032
Disclosure Date: December 28, 2020 (last updated February 22, 2025)
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from the network interface of the server. This may lead to disclosure of information from intranet systems.
0
Attacker Value
Unknown
CVE-2020-35712
Disclosure Date: December 26, 2020 (last updated February 22, 2025)
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
0
Attacker Value
Unknown
CVE-2020-8464
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access.
0
Attacker Value
Unknown
CVE-2019-14476
Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.
0
Attacker Value
Unknown
CVE-2020-26258
Disclosure Date: December 16, 2020 (last updated February 22, 2025)
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist if running Java 15 or higher. No user is affected who followed the recommendation to setup XStream's Security Framework with a whitelist! Anyone relying on XStream's default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.
0
Attacker Value
Unknown
CVE-2020-10770
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
0