{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aweavere_bridge/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:weaver:e_bridge:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2020-37278"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["e-Bridge"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","ssrf"],"_cs_type":"threat","_cs_vendors":["Weaver"],"content_html":"\u003cp\u003eWeaver e-Bridge contains a critical vulnerability (CVE-2020-37278) within its saveYZJFile endpoint that allows for both unauthenticated arbitrary file read and server-side request forgery (SSRF). By manipulating the downloadUrl parameter, a remote attacker can force the application to retrieve and expose local files, such as /etc/passwd, or leverage the server as a proxy to conduct SSRF attacks against internal network infrastructure. This vulnerability represents a significant risk for environments utilizing e-Bridge, as it facilitates credential theft, configuration leakage, and internal reconnaissance. Exploitation of this flaw has been observed in the wild since October 17, 2023, as documented by the Shadowserver Foundation. Defenders should prioritize patching and monitoring traffic directed toward the affected endpoint.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing instance of Weaver e-Bridge.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the saveYZJFile endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects a file:// URI into the downloadUrl parameter to target local files (e.g., /etc/passwd).\u003c/li\u003e\n\u003cli\u003eThe application processes the malicious parameter without sufficient input validation.\u003c/li\u003e\n\u003cli\u003eThe server reads the content of the specified local file from the disk.\u003c/li\u003e\n\u003cli\u003eThe server returns the contents of the file in the HTTP response body to the attacker.\u003c/li\u003e\n\u003cli\u003eAlternatively, the attacker injects an http(s):// URI into the downloadUrl parameter to probe internal services.\u003c/li\u003e\n\u003cli\u003eThe server performs the request as the internal host, allowing the attacker to bypass network perimeter controls.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to read arbitrary files from the host filesystem, potentially leading to full system compromise through the exposure of configuration files, keys, and credentials. Furthermore, the SSRF capability enables attackers to pivot into the internal network, perform port scanning, and interact with internal-only web services that are otherwise unreachable from the internet.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests to the saveYZJFile endpoint involving file:// or unexpected URL schemes in the downloadUrl parameter.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect exploitation attempts against the vulnerable endpoint.\u003c/li\u003e\n\u003cli\u003ePatch affected Weaver e-Bridge instances immediately as updates become available from the vendor.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the saveYZJFile endpoint at the firewall level if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T20:26:48Z","date_published":"2026-10-02T20:26:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-weaver-ebridge-arbitrary-file-read/","summary":"Weaver e-Bridge contains an unauthenticated arbitrary file read and SSRF vulnerability in the saveYZJFile endpoint, enabling attackers to access sensitive system files or scan internal network resources.","title":"Arbitrary File Read and SSRF Vulnerability in Weaver e-Bridge","url":"https://feed.craftedsignal.io/briefs/2026-10-weaver-ebridge-arbitrary-file-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:weaver:e_bridge:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}