API7:2023: Server Side Request Forgery (SSRF)
API fetches a remote resource without validating the user-supplied URL, allowing attackers to make the server reach internal/cloud-metadata endpoints.
How it's found
Identified by injecting internal and cloud-metadata URLs into every URL-accepting parameter to confirm the server fetches attacker-controlled destinations.
Standards mapping
- CWE
- CWE-918
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Server-Side Request Forgery (SSRF) using Vuln Scanner and Web Scanner, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness.
Tools: Vuln Scanner, Web Scanner
Frequently asked questions
What is API7:2023 Server Side Request Forgery (SSRF)?
API fetches a remote resource without validating the user-supplied URL, allowing attackers to make the server reach internal/cloud-metadata endpoints.
How do you find Server Side Request Forgery (SSRF)?
Identified by injecting internal and cloud-metadata URLs into every URL-accepting parameter to confirm the server fetches attacker-controlled destinations.
Which CWEs map to API7:2023?
API7:2023 maps to CWE-918.
Does TurboPentest test for Server Side Request Forgery (SSRF)?
TurboPentest's automated black-box pentest actively probes for Server-Side Request Forgery (SSRF) using Vuln Scanner and Web Scanner, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness.
Related OWASP categories
- OWASP API Security Top 10API1:2023: Broken Object Level Authorization
- OWASP API Security Top 10API2:2023: Broken Authentication
- OWASP API Security Top 10API3:2023: Broken Object Property Level Authorization
- OWASP API Security Top 10API4:2023: Unrestricted Resource Consumption
- OWASP API Security Top 10API5:2023: Broken Function Level Authorization
- OWASP API Security Top 10API6:2023: Unrestricted Access to Sensitive Business Flows
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest