VYPR

CWE-283

Unverified Ownership

BaseDraft

Description

The product does not properly verify that a critical resource is owned by the proper entity.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (24)

page 2 of 2
  • CVE-2026-15599LowAug 6, 2026
    risk 0.21cvss 3.3epss 0.00

    Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain-joiner: before 0.5.5.

  • CVE-2025-12815MedNov 6, 2025
    risk 0.21cvss 4.3epss 0.00

    An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview…

  • CVE-2023-6068LowMar 4, 2024
    risk 0.20cvss 3.1epss 0.00

    On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and some

  • CVE-2022-29220MedMay 31, 2022
    risk 0.00cvss 6.5epss 0.00

    github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check…