CWE-281
Improper Preservation of Permissions
Description
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (352)
page 14 of 18| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-57439 | Med | 0.32 | 4.9 | 0.01 | Jan 29, 2025 | An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account. | ||
| CVE-2024-46941 | Med | 0.31 | — | 0.00 | Jun 6, 2025 | SystemUI has an incorrect component protection setting, which allows access to specific information. | ||
| CVE-2022-32969 | Med | 0.31 | 5.9 | 0.01 | Jun 29, 2022 | MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue. | ||
| CVE-2026-34600 | Med | 0.30 | 5.7 | 0.00 | May 19, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully… | ||
| CVE-2024-44223 | Med | 0.30 | 4.6 | 0.00 | Dec 20, 2024 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window. | ||
| CVE-2024-37649 | Med | 0.30 | 4.6 | 0.00 | Dec 18, 2024 | Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials. | ||
| CVE-2024-50931 | Med | 0.30 | 4.6 | 0.00 | Dec 10, 2024 | Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions. | ||
| CVE-2024-43784 | Med | 0.30 | 5.7 | 0.00 | Nov 26, 2024 | lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that… | ||
| CVE-2020-15113 | Med | 0.30 | 5.7 | 0.00 | Aug 5, 2020 | In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the… | ||
| CVE-2025-26420 | Med | 0.29 | 4.4 | 0.00 | Sep 4, 2025 | In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction… | ||
| CVE-2024-22405 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2024 | XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive XADMaster may not apply quarantine attribute correctly. Such behaviour may circumvent Gatekeeper checks on the system. Only macOS installations… | ||
| CVE-2024-23560 | Med | 0.29 | 4.4 | 0.00 | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. | ||
| CVE-2021-38553 | Med | 0.29 | 4.4 | 0.00 | Aug 13, 2021 | HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0. | ||
| CVE-2026-58510 | Med | 0.28 | 4.3 | — | Aug 13, 2026 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||
| CVE-2024-53994 | Med | 0.28 | 4.3 | 0.00 | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to… | ||
| CVE-2024-52522 | Med | 0.28 | — | 0.00 | Nov 15, 2024 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions… | ||
| CVE-2024-22114 | Med | 0.28 | 4.3 | 0.01 | Aug 12, 2024 | User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard. | ||
| CVE-2024-33921 | Med | 0.28 | 4.3 | 0.00 | May 3, 2024 | Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21. | ||
| CVE-2024-1726 | Med | 0.28 | 5.3 | 0.01 | Apr 25, 2024 | A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has… | ||
| CVE-2024-3545 | Med | 0.28 | 4.3 | 0.00 | Apr 9, 2024 | Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining… |
- risk 0.32cvss 4.9epss 0.01
An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.
- risk 0.31cvss —epss 0.00
SystemUI has an incorrect component protection setting, which allows access to specific information.
- risk 0.31cvss 5.9epss 0.01
MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue.
- risk 0.30cvss 5.7epss 0.00
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully…
- risk 0.30cvss 4.6epss 0.00
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.
- risk 0.30cvss 4.6epss 0.00
Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials.
- risk 0.30cvss 4.6epss 0.00
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
- risk 0.30cvss 5.7epss 0.00
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that…
- risk 0.30cvss 5.7epss 0.00
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the…
- risk 0.29cvss 4.4epss 0.00
In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
- risk 0.29cvss 5.5epss 0.00
XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive XADMaster may not apply quarantine attribute correctly. Such behaviour may circumvent Gatekeeper checks on the system. Only macOS installations…
- risk 0.29cvss 4.4epss 0.00
HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.
- risk 0.29cvss 4.4epss 0.00
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
- risk 0.28cvss 4.3epss —
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- risk 0.28cvss 4.3epss 0.00
Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to…
- risk 0.28cvss —epss 0.00
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions…
- risk 0.28cvss 4.3epss 0.01
User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard.
- risk 0.28cvss 4.3epss 0.00
Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.
- risk 0.28cvss 5.3epss 0.01
A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has…
- risk 0.28cvss 4.3epss 0.00
Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining…