VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 63 of 80
  • CVE-2019-20882MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.

  • CVE-2020-8954MedJun 8, 2020
    risk 0.35cvss 5.4epss 0.01

    OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]

  • CVE-2020-13240MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

  • CVE-2020-2183MedMay 6, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access.

  • CVE-2020-12277MedApr 29, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

  • CVE-2020-4274MedApr 15, 2020
    risk 0.35cvss 5.4epss 0.01

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.

  • CVE-2020-7802MedApr 14, 2020
    risk 0.35cvss 5.3epss 0.01

    The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to insufficient default permissions, which could allow an attacker to view network…

  • CVE-2020-7977MedFeb 5, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

  • CVE-2020-7979MedFeb 5, 2020
    risk 0.35cvss 5.3epss 0.01

    GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

  • CVE-2020-6166MedJan 9, 2020
    risk 0.35cvss 5.4epss 0.01

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.

  • CVE-2019-16559MedDec 17, 2019
    risk 0.35cvss 5.4epss 0.01

    A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.

  • CVE-2019-19712MedDec 17, 2019
    risk 0.35cvss 5.3epss 0.01

    Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.

  • CVE-2019-14861MedDec 10, 2019
    risk 0.35cvss 5.3epss 0.02

    All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In…

  • CVE-2019-19118MedDec 2, 2019
    risk 0.35cvss 6.5epss 0.02

    Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI,…

  • CVE-2019-1982MedNov 5, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The…

  • CVE-2019-18369MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.

  • CVE-2019-18367MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

  • CVE-2019-18366MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.

  • CVE-2019-10472MedOct 23, 2019
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2019-10463MedOct 23, 2019
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.