VYPR

CWE-282

Improper Ownership Management

ClassDraft

Description

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-17 · CAPEC-35

CVEs mapped to this weakness (29)

page 2 of 2
  • CVE-2025-67642MedDec 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.

  • CVE-2025-1112MedJul 9, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users.

  • CVE-2025-3629MedJun 21, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management.

  • CVE-2025-32945MedApr 15, 2025
    risk 0.28cvss 4.3epss 0.00

    The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID…

  • CVE-2024-45103MedSep 13, 2024
    risk 0.28cvss 4.3epss 0.00

    A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.

  • CVE-2023-0989MedSep 29, 2023
    risk 0.28cvss 4.3epss 0.00

    An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to extract non-protected CI/CD variables by tricking a user to visit a fork with a malicious CI/CD…

  • CVE-2025-46416LowJun 27, 2025
    risk 0.19cvss 2.9epss 0.00

    The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and…

  • CVE-2023-0386HigKEVMar 22, 2023
    risk 0.16cvss 7.8epss 0.08

    A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a…

  • CVE-2026-50130HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered…