CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,561)
page 62 of 79| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26809 | Med | 0.35 | 5.3 | 0.02 | Nov 10, 2020 | SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of… | ||
| CVE-2020-3484 | Med | 0.35 | 5.3 | 0.01 | Aug 26, 2020 | A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to view potentially sensitive information on an affected device. The vulnerability is due to incorrect permissions within Apache… | ||
| CVE-2019-20882 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team. | ||
| CVE-2020-8954 | Med | 0.35 | 5.4 | 0.01 | Jun 8, 2020 | OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated] | ||
| CVE-2020-13240 | Med | 0.35 | 5.4 | 0.01 | May 20, 2020 | The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS. | ||
| CVE-2020-2183 | Med | 0.35 | 6.5 | 0.01 | May 6, 2020 | Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access. | ||
| CVE-2020-12277 | Med | 0.35 | 5.3 | 0.01 | Apr 29, 2020 | GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated. | ||
| CVE-2020-4274 | Med | 0.35 | 5.4 | 0.01 | Apr 15, 2020 | IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980. | ||
| CVE-2020-7802 | Med | 0.35 | 5.3 | 0.01 | Apr 14, 2020 | The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to insufficient default permissions, which could allow an attacker to view network… | ||
| CVE-2020-7977 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2020 | GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. | ||
| CVE-2020-7979 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission | ||
| CVE-2020-6166 | Med | 0.35 | 5.4 | 0.01 | Jan 9, 2020 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes. | ||
| CVE-2019-16559 | Med | 0.35 | 5.4 | 0.01 | Dec 17, 2019 | A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. | ||
| CVE-2019-19712 | Med | 0.35 | 5.3 | 0.01 | Dec 17, 2019 | Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them. | ||
| CVE-2019-14861 | Med | 0.35 | 5.3 | 0.02 | Dec 10, 2019 | All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In… | ||
| CVE-2019-19118 | Med | 0.35 | 6.5 | 0.02 | Dec 2, 2019 | Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI,… | ||
| CVE-2019-1982 | Med | 0.35 | 5.3 | 0.01 | Nov 5, 2019 | A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The… | ||
| CVE-2019-18369 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible. | ||
| CVE-2019-18367 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions. | ||
| CVE-2019-18366 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission. |
- risk 0.35cvss 5.3epss 0.02
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of…
- risk 0.35cvss 5.3epss 0.01
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to view potentially sensitive information on an affected device. The vulnerability is due to incorrect permissions within Apache…
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
- risk 0.35cvss 5.4epss 0.01
OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]
- risk 0.35cvss 5.4epss 0.01
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
- risk 0.35cvss 6.5epss 0.01
Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access.
- risk 0.35cvss 5.3epss 0.01
GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.
- risk 0.35cvss 5.4epss 0.01
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.
- risk 0.35cvss 5.3epss 0.01
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to insufficient default permissions, which could allow an attacker to view network…
- risk 0.35cvss 5.3epss 0.01
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
- risk 0.35cvss 5.3epss 0.01
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- risk 0.35cvss 5.4epss 0.01
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
- risk 0.35cvss 5.4epss 0.01
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.
- risk 0.35cvss 5.3epss 0.01
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
- risk 0.35cvss 5.3epss 0.02
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In…
- risk 0.35cvss 6.5epss 0.02
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI,…
- risk 0.35cvss 5.3epss 0.01
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The…
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.