CWE-268
Privilege Chaining
Description
Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (24)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1003 | Low | 0.21 | 3.3 | 0.01 | Mar 18, 2022 | One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | ||
| CVE-2021-3932 | Med | 0.21 | 4.3 | 0.00 | Nov 13, 2021 | twill is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2023-5839 | Hig | 0.00 | 7.8 | 0.00 | Oct 29, 2023 | Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9. | ||
| CVE-2023-2250 | Med | 0.00 | 6.7 | 0.00 | Apr 24, 2023 | A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account… |
- risk 0.21cvss 3.3epss 0.01
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
- risk 0.21cvss 4.3epss 0.00
twill is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 7.8epss 0.00
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
- risk 0.00cvss 6.7epss 0.00
A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account…