VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 69 of 79
  • CVE-2023-22931MedFeb 14, 2023
    risk 0.28cvss 4.3epss 0.00

    In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resource Description Format Site Summary (RSS) feeds without verifying permissions. This feature has been deprecated and disabled by default.

  • CVE-2022-42130MedNov 15, 2022
    risk 0.28cvss 4.3epss 0.01

    The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticated users to view and access…

  • CVE-2022-44548MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.

  • CVE-2020-5355MedOct 21, 2022
    risk 0.28cvss 4.3epss 0.00

    The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.

  • CVE-2021-44751MedMar 25, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform…

  • CVE-2022-27205MedMar 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

  • CVE-2022-27199MedMar 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.

  • CVE-2022-24343MedFeb 25, 2022
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

  • CVE-2022-0179MedJan 12, 2022
    risk 0.28cvss 5.4epss 0.01

    snipe-it is vulnerable to Missing Authorization

  • CVE-2021-40123MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted. This vulnerability is due to incorrect permissions…

  • CVE-2021-30999MedAug 24, 2021
    risk 0.28cvss 4.3epss 0.01

    The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be unable to fully delete browsing history.

  • CVE-2021-33334MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.01

    The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site…

  • CVE-2021-33324MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.01

    The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page…

  • CVE-2021-29052MedMay 17, 2021
    risk 0.28cvss 4.3epss 0.01

    The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authenticated users to view DDMStructures via…

  • CVE-2020-11997MedJan 19, 2021
    risk 0.28cvss 4.3epss 0.01

    Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP…

  • CVE-2020-26031MedDec 28, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).

  • CVE-2020-27358MedNov 2, 2020
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their conversation threads as CSV) allows non-privileged users to export one another's conversation threads by changing the thread_id parameter in the request…

  • CVE-2020-6527MedJul 22, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2020-6165MedJul 15, 2020
    risk 0.28cvss 5.3epss 0.01

    SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms. The automatic permission-checking mechanism in the silverstripe/graphql module does not provide complete protection against lists…

  • CVE-2019-20889MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.