Show filters
173 Total Results
Displaying 11-20 of 173
Sort by:
Attacker Value
Unknown
CVE-2020-19613
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.
0
Attacker Value
Unknown
CVE-2021-26072
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2021-1627
Disclosure Date: March 26, 2021 (last updated February 22, 2025)
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.
0
Attacker Value
Unknown
CVE-2021-26715
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usage of the logo_uri parameter in the Dynamic Client Registration request. An unauthenticated attacker can make a HTTP request from the vulnerable server to any address in the internal network and obtain its response (which might, for example, have a JavaScript payload for resultant XSS). The issue can be exploited to bypass network boundaries, obtain sensitive data, or attack other hosts in the internal network.
0
Attacker Value
Unknown
CVE-2020-15809
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.
0
Attacker Value
Unknown
CVE-2021-22179
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbound Requests feature.
0
Attacker Value
Unknown
CVE-2021-22178
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the Prometheus integration.
0
Attacker Value
Unknown
CVE-2021-21349
Disclosure Date: March 23, 2021 (last updated February 22, 2025)
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
0
Attacker Value
Unknown
CVE-2021-21342
Disclosure Date: March 23, 2021 (last updated February 22, 2025)
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in a server-side forgery request. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
0
Attacker Value
Unknown
CVE-2020-4882
Disclosure Date: March 19, 2021 (last updated February 22, 2025)
IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 190852.
0