VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (352)

page 14 of 18
  • CVE-2024-57439MedJan 29, 2025
    risk 0.32cvss 4.9epss 0.01

    An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.

  • CVE-2024-46941MedJun 6, 2025
    risk 0.31cvss epss 0.00

    SystemUI has an incorrect component protection setting, which allows access to specific information.

  • CVE-2022-32969MedJun 29, 2022
    risk 0.31cvss 5.9epss 0.01

    MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue.

  • CVE-2026-34600MedMay 19, 2026
    risk 0.30cvss 5.7epss 0.00

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully…

  • CVE-2024-44223MedDec 20, 2024
    risk 0.30cvss 4.6epss 0.00

    This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.

  • CVE-2024-37649MedDec 18, 2024
    risk 0.30cvss 4.6epss 0.00

    Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials.

  • CVE-2024-50931MedDec 10, 2024
    risk 0.30cvss 4.6epss 0.00

    Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

  • CVE-2024-43784MedNov 26, 2024
    risk 0.30cvss 5.7epss 0.00

    lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that…

  • CVE-2020-15113MedAug 5, 2020
    risk 0.30cvss 5.7epss 0.00

    In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the…

  • CVE-2025-26420MedSep 4, 2025
    risk 0.29cvss 4.4epss 0.00

    In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2024-22405MedApr 30, 2024
    risk 0.29cvss 5.5epss 0.00

    XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive XADMaster may not apply quarantine attribute correctly. Such behaviour may circumvent Gatekeeper checks on the system. Only macOS installations…

  • CVE-2024-23560MedApr 15, 2024
    risk 0.29cvss 4.4epss 0.00

    HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

  • CVE-2021-38553MedAug 13, 2021
    risk 0.29cvss 4.4epss 0.00

    HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

  • CVE-2026-58510MedAug 13, 2026
    risk 0.28cvss 4.3epss

    GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

  • CVE-2024-53994MedFeb 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to…

  • CVE-2024-52522MedNov 15, 2024
    risk 0.28cvss epss 0.00

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions…

  • CVE-2024-22114MedAug 12, 2024
    risk 0.28cvss 4.3epss 0.01

    User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.

  • CVE-2024-33921MedMay 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.

  • CVE-2024-1726MedApr 25, 2024
    risk 0.28cvss 5.3epss 0.01

    A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has…

  • CVE-2024-3545MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining…