COMMON WEAKNESS ENUMERATIONIncomplete
CWE-918
Server-Side Request Forgery (SSRF)
Abstraction
Base
Structure
Simple
Likelihood of Exploit
High
Understand the problem
What is the problem?
Terminology
Alternate terms and usages
XSPA
SSRF
Root cause
How and when does the problem arise?
Lifecycle phase
Architecture and Design
Lifecycle phase
Implementation
Risk
What does successful exploitation lead to?
Read Application Data
Execute Unauthorized Code or Commands
Bypass Protection Mechanism
Defence
How is it prevented and fixed?
- Maintain an allowlist of allowed domains/IPs
- Block requests to local/loopback and metadata IP addresses (169.254.169.254)
Verification
How is it detected?
Automated Static Analysis
HighMITRE diagram
Weakness relationships and flow
