Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27974
HistoryNov 24, 2020 - 7:16 a.m.

Server-Side Request Forgery (SSRF)

2020-11-2407:16:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
ssrf
vulnerable
private-ip
validation
insecure regular expressions
requests
attacker
library
ip addresses

EPSS

0.009

Percentile

83.2%

private-ip is vulnerable to server-side request forgery (SSRF). An application using the library allows an attacker to bypass the insecure regular expressions used to validate IP addresses, and perform requests on behalf of the server.

EPSS

0.009

Percentile

83.2%