VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 70 of 79
  • CVE-2020-6504MedJun 3, 2020
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.

  • CVE-2020-6488MedMay 21, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-12101MedApr 30, 2020
    risk 0.28cvss 4.3epss 0.02

    The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.

  • CVE-2020-6441MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.

  • CVE-2020-6431MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.

  • CVE-2020-10660MedMar 23, 2020
    risk 0.28cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.

  • CVE-2019-20106MedFeb 6, 2020
    risk 0.28cvss 4.3epss 0.01

    Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control…

  • CVE-2020-7967MedFeb 5, 2020
    risk 0.28cvss 4.3epss 0.01

    GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

  • CVE-2013-4764MedDec 27, 2019
    risk 0.28cvss 4.3epss 0.00

    Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.

  • CVE-2019-16552MedDec 17, 2019
    risk 0.28cvss 5.4epss 0.01

    A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials, or determine the existence of a file with a given path on…

  • CVE-2019-15011MedDec 17, 2019
    risk 0.28cvss 4.3epss 0.01

    The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to…

  • CVE-2019-10465MedOct 23, 2019
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins…

  • CVE-2017-9505MedJun 15, 2017
    risk 0.28cvss 4.3epss 0.01

    Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of…

  • CVE-2025-54990MedNov 18, 2025
    risk 0.27cvss 5.3epss 0.00

    XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is…

  • CVE-2024-6476MedNov 26, 2024
    risk 0.27cvss 4.2epss 0.00

    Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted flaw. Please refer to…

  • CVE-2024-25605MedFeb 20, 2024
    risk 0.27cvss 5.3epss 0.00

    The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which…

  • CVE-2022-41414MedOct 7, 2022
    risk 0.27cvss 5.3epss 0.00

    An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.

  • CVE-2020-29503MedJul 19, 2021
    risk 0.27cvss 4.1epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file permission Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information disclosure of certain system directory.

  • CVE-2026-48722medJun 25, 2026
    risk 0.26cvss epss

    ### Impact `nextflow auth login` persists Seqera Platform OIDC tokens to `${NXF_HOME:-~/.nextflow}/seqera-auth.config`. The file is created via Java NIO without specifying file permissions, so under the default `umask 022` it lands at mode `0644` (world-readable). On a…

  • CVE-2025-32803MedMay 28, 2025
    risk 0.26cvss 4.0epss 0.00

    In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.