VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 183 of 186
  • CVE-2022-1227HigApr 29, 2022
    risk 0.00cvss 8.8epss 0.04

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the…

  • CVE-2022-24842HigApr 12, 2022
    risk 0.00cvss 8.8epss 0.02

    MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user is able to create service accounts for root or other admin users and then is able to assume their access policies via the…

  • CVE-2022-24750HigMar 10, 2022
    risk 0.00cvss 8.8epss 0.00

    UltraVNC is a free and open source remote pc access software. A vulnerability has been found in versions prior to 1.3.8.0 in which the DSM plugin module, which allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system. The vulnerability…

  • CVE-2022-25636HigFeb 24, 2022
    risk 0.00cvss 7.8epss 0.03

    net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.

  • CVE-2022-25372HigFeb 20, 2022
    risk 0.00cvss 7.8epss 0.01

    Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.

  • CVE-2022-23604HigFeb 15, 2022
    risk 0.00cvss 8.8epss 0.01

    x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderation. A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users…

  • CVE-2021-45330CriFeb 9, 2022
    risk 0.00cvss 9.8epss 0.01

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

  • CVE-2021-3813MedFeb 9, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.

  • CVE-2021-43860HigJan 12, 2022
    risk 0.00cvss 8.2epss 0.01

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…

  • CVE-2022-23117HigJan 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.

  • CVE-2021-28680HigDec 7, 2021
    risk 0.00cvss 8.1epss 0.01

    The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this…

  • CVE-2021-43793MedDec 1, 2021
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Discourse

  • CVE-2021-33505HigJul 15, 2021
    risk 0.00cvss 7.8epss 0.00

    A local malicious user can circumvent the Falco detection engine through 0.28.1 by running a program that alters arguments of system calls being executed. Issue is fixed in Falco versions >= 0.29.1.

  • CVE-2021-21430MedMay 10, 2021
    risk 0.00cvss 6.2epss 0.00

    OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure temporary files that can leave…

  • CVE-2021-21428CriMay 10, 2021
    risk 0.00cvss 9.3epss 0.00

    Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folders with File.createTempFile during the…

  • CVE-2020-27519HigApr 30, 2021
    risk 0.00cvss 7.8epss 0.00

    Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the log and log-append along with log injection to create or append to privileged…

  • CVE-2020-35517HigJan 28, 2021
    risk 0.00cvss 8.2epss 0.01

    A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

  • CVE-2020-15862HigAug 20, 2020
    risk 0.00cvss 7.8epss 0.00

    Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

  • CVE-2020-15149CriAug 20, 2020
    risk 0.00cvss 9.9epss 0.02

    NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation…

  • CVE-2020-14316CriJul 29, 2020
    risk 0.00cvss 9.9epss 0.02

    A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful exploitation allows an attacker to assume the privileges of the VM process on the host system. In worst-case scenarios an attacker can…