VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 160 of 164
  • CVE-2024-28241HigApr 25, 2024
    risk 0.00cvss 7.3epss 0.00

    The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DLLs to modify agent logic and even gain higher privileges. Users should upgrade to GLPI-Agent 1.7.2 to receive a patch. As a workaround, use the default…

  • CVE-2024-28247HigMar 27, 2024
    risk 0.00cvss 7.6epss 0.01

    The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files arbitrarily, and because the…

  • CVE-2024-28851MedMar 15, 2024
    risk 0.00cvss 4.0epss 0.00

    The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider…

  • CVE-2024-27301HigMar 14, 2024
    risk 0.00cvss 7.3epss 0.00

    Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang…

  • CVE-2024-0439HigFeb 26, 2024
    risk 0.00cvss 8.8epss 0.01

    As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a…

  • CVE-2024-21638CriJan 10, 2024
    risk 0.00cvss 9.1epss 0.02

    Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as the Service Principal…

  • CVE-2023-51386HigDec 22, 2023
    risk 0.00cvss 7.8epss 0.00

    Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting…

  • CVE-2023-41036HigNov 7, 2023
    risk 0.00cvss 7.8epss 0.00

    Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead to a privilege escalation. Distributed objects are a concept introduced by Apple which allow one program to vend an interface to…

  • CVE-2023-5408HigNov 2, 2023
    risk 0.00cvss 7.2epss 0.01

    A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader…

  • CVE-2023-41053LowSep 6, 2023
    risk 0.00cvss 3.3epss 0.00

    Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration. The problem exists in Redis 7.0…

  • CVE-2023-39520MedAug 7, 2023
    risk 0.00cvss 5.5epss 0.00

    Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local privilege escalation for low privileged users, via the `repair` function. The problem occurs as the repair function of the MSI is…

  • CVE-2023-37907HigJul 25, 2023
    risk 0.00cvss 7.0epss 0.00

    Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homepage allows local privilege escalation (LPE) for low privileged users, if already installed. The problem occurs as the repair…

  • CVE-2023-32696HigMay 30, 2023
    risk 0.00cvss 8.8epss 0.01

    CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and configuration files in the docker container and the `ckan` user had the permissions to use sudo.…

  • CVE-2023-1326HigApr 13, 2023
    risk 0.00cvss 7.7epss 0.01

    A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local…

  • CVE-2023-28855MedApr 5, 2023
    risk 0.00cvss 6.5epss 0.01

    Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access.…

  • CVE-2023-0664HigMar 29, 2023
    risk 0.00cvss 7.8epss 0.00

    A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.

  • CVE-2023-27589MedMar 14, 2023
    risk 0.00cvss 6.5epss 0.01

    Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. Once this user is created…

  • CVE-2023-25149HigFeb 14, 2023
    risk 0.00cvss 8.8epss 0.01

    TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run as part of the telemetry data…

  • CVE-2022-3422HigOct 7, 2022
    risk 0.00cvss 7.5epss 0.01

    Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass

  • CVE-2022-36075LowSep 15, 2022
    risk 0.00cvss 2.6epss 0.00

    Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access…