VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (352)

page 16 of 18
  • CVE-2025-14779LowAug 6, 2026
    risk 0.25cvss 3.8epss 0.00

    The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all…

  • CVE-2025-0914LowFeb 27, 2025
    risk 0.25cvss 3.8epss 0.00

    An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments where this was explicitly forbidden by configuring the prevent_execve flag in the configuration file. This…

  • CVE-2024-39902MedJul 22, 2024
    risk 0.24cvss 4.8epss 0.00

    Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8, the checkbox "Apply same permissions to all sub-items of this folder" in the document…

  • CVE-2025-24791MedJan 29, 2025
    risk 0.22cvss 4.4epss 0.00

    snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache…

  • CVE-2025-9615LowJan 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from…

  • CVE-2023-32199MedOct 29, 2025
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule…

  • CVE-2025-27563LowJun 8, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

  • CVE-2025-26693LowJun 8, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

  • CVE-2024-54516LowJan 27, 2025
    risk 0.21cvss 3.3epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to approve a launch daemon without user consent.

  • CVE-2024-22177LowApr 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.

  • CVE-2023-1386LowJul 24, 2023
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by…

  • CVE-2022-31237LowAug 22, 2022
    risk 0.21cvss 3.3epss 0.00

    Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to limited information disclosure.

  • CVE-2022-28147MedMar 29, 2022
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2019-19620LowDec 6, 2019
    risk 0.21cvss 3.3epss 0.00

    In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to the collection of process-execution telemetry, for executions against specific…

  • CVE-2020-13282LowAug 13, 2020
    risk 0.20cvss 3.1epss 0.01

    For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

  • CVE-2024-47270LowMay 27, 2026
    risk 0.18cvss 2.7epss 0.00

    Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

  • CVE-2022-41963LowDec 16, 2022
    risk 0.18cvss 2.7epss 0.00

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The…

  • CVE-2020-13308LowSep 15, 2020
    risk 0.18cvss 2.7epss 0.02

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.

  • CVE-2019-18458LowNov 26, 2019
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

  • CVE-2024-38361LowJun 20, 2024
    risk 0.17cvss 3.7epss 0.00

    Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when permission is expected. If the resource…