VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (357)

page 17 of 18
  • CVE-2024-47270LowMay 27, 2026
    risk 0.18cvss 2.7epss 0.00

    Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

  • CVE-2022-41963LowDec 16, 2022
    risk 0.18cvss 2.7epss 0.00

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The…

  • CVE-2020-13308LowSep 15, 2020
    risk 0.18cvss 2.7epss 0.02

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.

  • CVE-2019-18458LowNov 26, 2019
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

  • CVE-2024-38361LowJun 20, 2024
    risk 0.17cvss 3.7epss 0.00

    Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when permission is expected. If the resource…

  • CVE-2021-39897LowNov 5, 2021
    risk 0.17cvss 2.6epss 0.01

    Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred

  • CVE-2026-35361LowApr 22, 2026
    risk 0.15cvss 3.4epss 0.00

    The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std::fs::remove_dir, which cannot remove device nodes or FIFOs. This leaves…

  • CVE-2021-20263LowMar 9, 2021
    risk 0.14cvss 3.3epss 0.00

    A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare…

  • CVE-2024-32882LowMay 2, 2024
    risk 0.11cvss 2.7epss 0.00

    Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` has been used to further…

  • CVE-2021-41089LowOct 4, 2021
    risk 0.11cvss 2.8epss 0.00

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the…

  • CVE-2026-44947MedJun 30, 2026
    risk 0.00cvss —epss 0.00

    A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from…

  • CVE-2025-32697NonApr 10, 2025
    risk 0.00cvss —epss 0.00

    Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php. This issue…

  • CVE-2025-32696NonApr 10, 2025
    risk 0.00cvss —epss 0.00

    Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.

  • CVE-2024-41650CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.00

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.

  • CVE-2024-41649CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.

  • CVE-2024-41648CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.00

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.

  • CVE-2024-41646CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.

  • CVE-2024-41645CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.

  • CVE-2024-41644CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.

  • CVE-2024-37882HigJun 14, 2024
    risk 0.00cvss 8.1epss 0.01

    Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise…