Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Batik HIGH 8.2
CVE-2020-11987EPSS 14%

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf…

Fix: after 1.13
Fix from $1,950 2021-02-24
Xmlgraphics Commons HIGH 8.2
CVE-2020-11988EPSS 7%

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi…

Fix: after 2.4
Fix from $1,950 2021-02-24
Struts HIGH 7.7
CVE-2020-26258EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability c…

Fix: 1.4.15 / 6.0.0+
Fix from $1,950 2020-12-16
Airflow MEDIUM 5.3
CVE-2020-17513

In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

Fix: 1.10.13+
Fix from $1,600 2020-12-14
Batik HIGH 7.5
CVE-2019-17566EPSS 11%

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-c…

Fix: 1.13+
Fix from $1,950 2020-11-12
Karaf MEDIUM 6.3
CVE-2020-11980

In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…

Fix: 4.2.9+
Fix from $1,600 2020-06-12
Olingo HIGH 7.5
CVE-2020-1925

Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or D…

Fix: after 4.7.0
Fix from $1,950 2020-01-09
Roller CRITICAL 9.8
CVE-2018-17198

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java S…

Fix: after 5.1.2
Fix from $2,300 2019-05-28
Axis HIGH 7.5
CVE-2019-0227EPSS 92%

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits…

Patch available
Fix from $1,950 2019-05-01
Solr HIGH 7.5
CVE-2017-3164EPSS 19%

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist …

Fix: after 7.6.0
Fix from $1,950 2019-03-08
Mesos MEDIUM 6.5
CVE-2018-1000421

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read …

Fix: after 0.17.1
Fix from $1,600 2019-01-09
Camel HIGH 7.4
CVE-2017-5643EPSS 6%

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

Fix: after 2.16.0
Fix from $1,950 2017-03-16