VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 62 of 79
  • CVE-2020-26809MedNov 10, 2020
    risk 0.35cvss 5.3epss 0.02

    SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of…

  • CVE-2020-3484MedAug 26, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to view potentially sensitive information on an affected device. The vulnerability is due to incorrect permissions within Apache…

  • CVE-2019-20882MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.

  • CVE-2020-8954MedJun 8, 2020
    risk 0.35cvss 5.4epss 0.01

    OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]

  • CVE-2020-13240MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

  • CVE-2020-2183MedMay 6, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access.

  • CVE-2020-12277MedApr 29, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

  • CVE-2020-4274MedApr 15, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.

  • CVE-2020-7802MedApr 14, 2020
    risk 0.35cvss 5.3epss 0.01

    The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to insufficient default permissions, which could allow an attacker to view network…

  • CVE-2020-7977MedFeb 5, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

  • CVE-2020-7979MedFeb 5, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

  • CVE-2020-6166MedJan 9, 2020
    risk 0.35cvss 5.4epss 0.01

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.

  • CVE-2019-16559MedDec 17, 2019
    risk 0.35cvss 5.4epss 0.01

    A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.

  • CVE-2019-19712MedDec 17, 2019
    risk 0.35cvss 5.3epss 0.01

    Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.

  • CVE-2019-14861MedDec 10, 2019
    risk 0.35cvss 5.3epss 0.02

    All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In…

  • CVE-2019-19118MedDec 2, 2019
    risk 0.35cvss 6.5epss 0.02

    Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI,…

  • CVE-2019-1982MedNov 5, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The…

  • CVE-2019-18369MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.

  • CVE-2019-18367MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

  • CVE-2019-18366MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.