VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 77 of 79
  • CVE-2022-27650HigApr 4, 2022
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker…

  • CVE-2021-22571MedMar 18, 2022
    risk 0.00cvss 5.5epss 0.00

    A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.

  • CVE-2021-3155LowFeb 17, 2022
    risk 0.00cvss 3.8epss 0.00

    snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

  • CVE-2022-24301MedFeb 2, 2022
    risk 0.00cvss 6.5epss 0.01

    In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.

  • CVE-2021-41166MedJan 26, 2022
    risk 0.00cvss 4.3epss 0.01

    The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may…

  • CVE-2022-21704MedJan 19, 2022
    risk 0.00cvss 5.5epss 0.00

    log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any…

  • CVE-2021-43860HigJan 12, 2022
    risk 0.00cvss 8.2epss 0.01

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…

  • CVE-2021-44833CriDec 12, 2021
    risk 0.00cvss 9.8epss 0.02

    The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

  • CVE-2021-32725LowJul 12, 2021
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3.…

  • CVE-2021-33506HigMay 26, 2021
    risk 0.00cvss 7.5epss 0.01

    jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circumvent conference moderation.

  • CVE-2021-33038HigMay 26, 2021
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web…

  • CVE-2020-26088MedSep 24, 2020
    risk 0.00cvss 5.5epss 0.00

    A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.

  • CVE-2020-24717HigAug 27, 2020
    risk 0.00cvss 7.8epss 0.00

    OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.

  • CVE-2020-15145MedAug 14, 2020
    risk 0.00cvss 6.7epss 0.00

    In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user may modify the existing `C:\ProgramData\ComposerSetup\bin\composer.bat` in order…

  • CVE-2020-15852HigJul 20, 2020
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization…

  • CVE-2020-8933HigJun 22, 2020
    risk 0.00cvss 7.8epss 0.00

    A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and…

  • CVE-2020-8907HigJun 22, 2020
    risk 0.00cvss 7.8epss 0.00

    A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" group, an attacker with this role is able to…

  • CVE-2020-8903HigJun 22, 2020
    risk 0.00cvss 7.8epss 0.00

    A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read…

  • CVE-2020-14156HigJun 15, 2020
    risk 0.00cvss 8.8epss 0.02

    user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.

  • CVE-2020-13867MedJun 5, 2020
    risk 0.00cvss 5.5epss 0.00

    Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).