VYPR

CWE-277

Insecure Inherited Permissions

VariantDraft

Description

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (74)

page 1 of 4
  • CVE-2024-36540CriJul 24, 2024
    risk 0.64cvss 9.8epss 0.00

    Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2024-36539CriJul 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2026-7891CriMay 7, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This…

  • CVE-2024-36542HigJul 25, 2024
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

  • CVE-2024-6605HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.00

    Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

  • CVE-2023-27842HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.02

    Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent

  • CVE-2021-41170CriNov 8, 2021
    risk 0.57cvss 9.8epss 0.02

    neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a…

  • CVE-2016-6811HigApr 11, 2017
    risk 0.57cvss 8.8epss 0.03

    In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

  • CVE-2024-34329HigJul 22, 2024
    risk 0.55cvss 8.4epss 0.01

    Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.

  • CVE-2024-29417HigMay 3, 2024
    risk 0.55cvss 8.4epss 0.00

    Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.

  • CVE-2024-7143HigAug 7, 2024
    risk 0.54cvss 8.3epss 0.01

    A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the…

  • CVE-2026-30266HigApr 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file

  • CVE-2024-27848HigJun 10, 2024
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.

  • CVE-2024-27822HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.

  • CVE-2024-23233HigMar 8, 2024
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.

  • CVE-2023-33990HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an…

  • CVE-2025-20008HigMay 13, 2025
    risk 0.50cvss 7.7epss 0.00

    Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-42681HigAug 15, 2024
    risk 0.50cvss 8.8epss 0.01

    Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.

  • CVE-2024-39877HigJul 17, 2024
    risk 0.50cvss 8.8epss 0.02

    Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users…

  • CVE-2024-41601HigJul 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.