A10:2021 – Server-Side Request Forgery (SSRF).¶
OWASP. (2021). A10:2021 – Server-Side Request Forgery (SSRF). OWASP Top 10:2021.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Confused Deputy
- The target T is an internal resource — a cloud metadata endpoint or an internal admin service — reachable only from inside the trust boundary.
This sourceDescribes SSRF — a server fetching an attacker-supplied URL reaches internal resources on its own authority — and allowlist/validation defenses.
- The target T is an internal resource — a cloud metadata endpoint or an internal admin service — reachable only from inside the trust boundary.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:836993c77f67 · see in the full table