VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (352)

page 13 of 18
  • CVE-2021-22137MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the…

  • CVE-2020-14958MedJun 21, 2020
    risk 0.35cvss 6.5epss 0.01

    In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.

  • CVE-2020-9781MedApr 1, 2020
    risk 0.35cvss 5.3epss 0.01

    The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.

  • CVE-2020-8633MedFeb 18, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calendar in Outlook, the calendar stayed mounted and accessible.

  • CVE-2019-16539MedNov 21, 2019
    risk 0.35cvss 6.5epss 0.01

    A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles.

  • CVE-2019-6791MedSep 9, 2019
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its…

  • CVE-2019-6995MedSep 9, 2019
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

  • CVE-2026-39828MedMay 22, 2026
    risk 0.34cvss 6.3epss 0.00

    When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with…

  • CVE-2024-9333MedOct 2, 2024
    risk 0.34cvss epss 0.00

    Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation

  • CVE-2024-28152MedMar 6, 2024
    risk 0.34cvss 6.3epss 0.01

    In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when…

  • CVE-2023-22738MedMar 1, 2023
    risk 0.34cvss 6.3epss 0.00

    vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization…

  • CVE-2022-48296MedFeb 9, 2023
    risk 0.34cvss 5.3epss 0.00

    The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices.

  • CVE-2022-47547MedDec 19, 2022
    risk 0.34cvss 5.3epss 0.01

    GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbehaves by never forwarding topic messages.

  • CVE-2022-36102MedSep 12, 2022
    risk 0.34cvss 6.3epss 0.01

    Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current…

  • CVE-2021-37056MedDec 7, 2021
    risk 0.34cvss 5.3epss 0.01

    There is an Improper permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to obtain certain device information.

  • CVE-2021-41091MedOct 4, 2021
    risk 0.34cvss 6.3epss 0.03

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise…

  • CVE-2024-2819MedJul 2, 2024
    risk 0.33cvss 5.1epss 0.00

    Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.

  • CVE-2023-30735MedOct 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant.

  • CVE-2023-28642MedMar 29, 2023
    risk 0.33cvss 6.1epss 0.00

    runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by…

  • CVE-2021-45446MedNov 2, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources…