VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (2,580)

page 111 of 129
  • CVE-2023-51661Dec 22, 2023
    risk 0.00cvss epss 0.00

    Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can access the filesystem outside of the sandbox. Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host…

  • CVE-2023-50783Dec 21, 2023
    risk 0.00cvss epss 0.00

    Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.…

  • CVE-2023-47327Dec 13, 2023
    risk 0.00cvss epss 0.00

    The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.

  • CVE-2023-47321Dec 13, 2023
    risk 0.00cvss epss 0.00

    Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

  • CVE-2023-47320Dec 13, 2023
    risk 0.00cvss epss 0.00

    Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users.…

  • CVE-2023-47325Dec 13, 2023
    risk 0.00cvss epss 0.00

    Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.

  • CVE-2023-32065Nov 28, 2023
    risk 0.00cvss epss 0.00

    OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.

  • CVE-2023-32064Nov 28, 2023
    risk 0.00cvss epss 0.00

    OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in…

  • CVE-2023-32063Nov 28, 2023
    risk 0.00cvss epss 0.00

    OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and…

  • CVE-2023-32062Nov 27, 2023
    risk 0.00cvss epss 0.00

    OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.

  • CVE-2023-6202Nov 27, 2023
    risk 0.00cvss epss 0.00

    Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.

  • CVE-2023-47865Nov 27, 2023
    risk 0.00cvss epss 0.00

    Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a…

  • CVE-2023-5549Nov 9, 2023
    risk 0.00cvss epss 0.00

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

  • CVE-2023-5542Nov 9, 2023
    risk 0.00cvss epss 0.00

    Students in "Only see own membership" groups could see other students in the group, which should be hidden.

  • CVE-2023-47110Nov 9, 2023
    risk 0.00cvss epss 0.00

    blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in…

  • CVE-2023-5976Nov 7, 2023
    risk 0.00cvss epss 0.00

    Improper Access Control in GitHub repository microweber/microweber prior to 2.0.

  • CVE-2023-44794Oct 25, 2023
    risk 0.00cvss epss 0.02

    An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

  • CVE-2023-41882Oct 11, 2023
    risk 0.00cvss epss 0.00

    vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However,…

  • CVE-2023-36820Oct 9, 2023
    risk 0.00cvss epss 0.00

    Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC…

  • CVE-2023-36465Oct 6, 2023
    risk 0.00cvss epss 0.00

    Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to…