{"id":"CVE-2023-41327","summary":"Controlled SSRF through URL in the WireMock","details":"WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first. \n\nUntil WireMock Webhooks Extension 3.0.0-beta-15, the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings. Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers. This issue has been addressed in versions 2.35.1 and 3.0.3 of wiremock. Wiremock studio has been discontinued and will not see a fix. Users unable to upgrade should use external firewall rules to define the list of permitted destinations.","aliases":["BIT-wiremock-2023-41327","GHSA-hq8w-9w8w-pmx7"],"modified":"2026-08-12T03:51:38.843327916Z","published":"2023-09-06T20:38:45.161Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41327.json","unresolved_ranges":[{"extracted_events":[{"introduced":" org.wiremock:wiremock-webhooks-extension: \u003e= 2.0.0, \u003c 2.35.1"},{"last_affected":" org.wiremock:wiremock-webhooks-extension: \u003e= 2.0.0, \u003c 2.35.1"},{"introduced":" org.wiremock:wiremock-webhooks-extension: \u003e= 3.0.0, \u003c 3.0.3"},{"last_affected":" org.wiremock:wiremock-webhooks-extension: \u003e= 3.0.0, \u003c 3.0.3"},{"introduced":" wiremock-studio: All versions"},{"last_affected":" wiremock-studio: All versions"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-918"]},"references":[{"type":"WEB","url":"https://github.com/wiremock/wiremock/releases/tag/3.0.0-beta-15"},{"type":"WEB","url":"https://wiremock.org/docs/configuration/#preventing-proxying-to-and-recording-from-specific-target-addresses"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41327.json"},{"type":"ADVISORY","url":"https://github.com/wiremock/wiremock/security/advisories/GHSA-hq8w-9w8w-pmx7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41327"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/holomekc/wiremock","events":[{"introduced":"0"},{"fixed":"87063432febaa9c10e90c92edb1d5a8f7afabae2"},{"introduced":"00b664a979455bf2b1bc2f01efa9724656dd1868"},{"fixed":"7a5126498182fd1c5036128244ede631e790804e"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.35.1"},{"introduced":"3.0.0"},{"fixed":"3.0.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:wiremock:wiremock:*:*:*:*:*:*:*:*"}}],"versions":["2.35.0","3.0.2","3.0.1","3.0.0","2.34.0","2.33.2","2.33.1","2.33.0","2.32.0","2.31.0","2.30.1","2.30.0","2.29.1-beta","2.29.0","2.29.0-beta2","2.29.0-beta","2.28.1","2.28.0","2.27.2","2.27.1","2.27.0","2.26.3","2.26.2","2.26.1","2.26.0","2.25.1","2.25.0","2.24.1","2.24.0","2.23.2","2.23.1","2.23.0","2.22.0","2.21.0","2.20.0","2.19.0","2.18.0","2.10.0","2.17.0","2.16.0","2.15.0","2.14.0","2.13.0","2.11.0","2.12.0","2.10.1","untagged-bdf8e8f86ab0c597e274","untagged-4e03592d74721087f03c","2.9.0","2.8.0","2.7.0","2.7.1","2.6.0","2.5.0","2.4.1","2.3.1","2.2.2","2.2.1","2.1.10","2.1.9","2.1.8","2.1.7","2.1.6","2.1.5-rc4","2.1.4-rc3","2.1.3-rc2","2.1.2-rc1","1.58","1.57","1.56","1.55","1.54","1.53","1.52-beta","1.52","1.51","1.50","1.49","1.48","1.47","1.46","1.44","1.43","1.42","1.41","1.40","1.39","1.38","1.37","1.36","1.33","release-1.25","release-1.14"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-41327.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/wiremock/wiremock","events":[{"introduced":"0"},{"fixed":"87063432febaa9c10e90c92edb1d5a8f7afabae2"},{"introduced":"00b664a979455bf2b1bc2f01efa9724656dd1868"},{"fixed":"7a5126498182fd1c5036128244ede631e790804e"},{"fixed":"e3c31bf25b319cfe6645d7038beab49b49fef391"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:wiremock:wiremock:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.35.1"},{"introduced":"3.0.0"},{"fixed":"3.0.3"}]}}],"versions":["2.35.0","3.0.2","3.0.1","3.0.0","3.0.0-beta-14","3.0.0-beta-13","3.0.0-beta-12","3.0.0-beta-11","3.0.0-beta-10","3.0.0-beta-9","3.0.0-beta-8","3.0.0-beta-7","3.0.0-beta-6","3.0.0-beta-5","3.0.0-beta-4","3.0.0-beta-3","3.0.0-beta-2","3.0.0-beta-1","2.34.0","2.33.2","2.33.1","2.33.0","2.32.0","2.31.0","2.30.1","2.30.0","2.29.1-beta","2.29.0","2.29.0-beta2","2.29.0-beta","2.28.1","2.28.0","2.27.2","2.27.1","2.27.0","2.26.3","2.26.2","2.26.1","2.26.0","2.25.1","2.25.0","2.24.1","2.24.0","2.23.2","2.23.1","2.23.0","2.22.0","2.21.0","2.20.0","2.19.0","2.18.0","2.17.0","2.16.0","2.15.0","2.14.0","2.13.0","2.11.0","2.12.0","2.10.1","2.10.0","2.9.0","2.8.0","2.7.0","2.7.1","2.6.0","2.5.0","2.4.1","2.3.1","2.2.2","2.2.1","2.1.10","2.1.9","2.1.8","2.1.7","2.1.6","2.1.5-rc4","2.1.4-rc3","2.1.3-rc2","2.1.2-rc1","1.58","1.57","1.56","1.55","1.54","1.53","1.52-beta","1.52","1.51","1.50","1.49","1.48","1.47","1.46","1.44","1.43","1.42","1.41","1.40","1.39","1.38","1.37","1.36","1.33","release-1.25","release-1.14"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-41327.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"}]}