Skip to content

[Apiiro] Dynatrace testing · Critical Risk #2

@ohadr-apiiro

Description

@ohadr-apiiro

asdasdasdada

Discovered on: Sep 16, 2025 21:18

Finding details
Finding name: Server-side Request Forgery (SSRF)
Severity: Medium
Sources: Dynatrace

About this vulnerability
Description: Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the ?url parameter, which was intended to allow displaying remote OpenAPI definitions. This functionality may pose a risk for users who host their own SwaggerUI instances. In particular, including remote OpenAPI definitions opens a vector for phishing attacks by abusing the trusted names/domains of self-hosted instances.

NOTE: This vulnerability has also been identified as: CVE-2018-25031
Identifiers:
- CVE-2021-46708

CVSS v3.1.0: 5.4
Exploit maturity: No exploit maturity data

Affected assets
Dependency: Swashbuckle.AspNetCore.SwaggerUI: 5.4.1.0

Repository: WebGoat
View in Apiiro

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions