VYPR

CWE-270

Privilege Context Switching Error

BaseDraft

Description

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-17 · CAPEC-30 · CAPEC-35

CVEs mapped to this weakness (26)

page 2 of 2
  • CVE-2024-51987MedNov 8, 2024
    risk 0.28cvss 5.4epss 0.00

    Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's access token after a token refresh occurs. This occurs because a refreshed…

  • CVE-2020-7020LowOct 22, 2020
    risk 0.20cvss 3.1epss 0.01

    Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the…

  • CVE-2021-3493HigKEVApr 17, 2021
    risk 0.19cvss 8.8epss 0.49

    The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu…

  • CVE-2025-49583LowJun 13, 2025
    risk 0.16cvss 3.5epss 0.00

    XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No…

  • CVE-2025-55210HigFeb 12, 2026
    risk 0.00cvss 7.5epss 0.00

    FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authenticated users with REST/GraphQL API access. This vulnerability allows an attacker to…

  • CVE-2017-2663HigJul 27, 2018
    risk 0.00cvss 8.2epss 0.00

    It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch…