CWE-918
Server-Side Request Forgery (SSRF)
About
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Common consequences
- Confidentiality → Read Application Data
- Integrity → Execute Unauthorized Code or Commands
- Access Control → Bypass Protection Mechanism
CVEs with this weakness
Frequently asked questions
What is CWE-918?
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. Common consequences Confidentiality → Read Application Data Integrity → Execute Unauthorized Code or Commands Access Control → Bypass Protection Mechanism
Which platforms does CWE-918 affect?
CWE-918 has been observed on: Web Based, AI/ML, Web Server.
How many CVEs does Rainforest track for CWE-918?
Rainforest Labs currently tracks 2 published CVEs mapped to CWE-918. They are listed on this page.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
