CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (2,580)
page 111 of 129| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-51661 | 0.00 | — | 0.00 | Dec 22, 2023 | Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can access the filesystem outside of the sandbox. Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host… | |||
| CVE-2023-50783 | 0.00 | — | 0.00 | Dec 21, 2023 | Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.… | |||
| CVE-2023-47327 | — | 0.00 | — | 0.00 | Dec 13, 2023 | The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL. | ||
| CVE-2023-47321 | — | 0.00 | — | 0.00 | Dec 13, 2023 | Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets. | ||
| CVE-2023-47320 | — | 0.00 | — | 0.00 | Dec 13, 2023 | Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users.… | ||
| CVE-2023-47325 | — | 0.00 | — | 0.00 | Dec 13, 2023 | Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces. | ||
| CVE-2023-32065 | — | 0.00 | — | 0.00 | Nov 28, 2023 | OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1. | ||
| CVE-2023-32064 | — | 0.00 | — | 0.00 | Nov 28, 2023 | OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in… | ||
| CVE-2023-32063 | — | 0.00 | — | 0.00 | Nov 28, 2023 | OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and… | ||
| CVE-2023-32062 | — | 0.00 | — | 0.00 | Nov 27, 2023 | OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1. | ||
| CVE-2023-6202 | 0.00 | — | 0.00 | Nov 27, 2023 | Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards. | |||
| CVE-2023-47865 | 0.00 | — | 0.00 | Nov 27, 2023 | Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a… | |||
| CVE-2023-5549 | 0.00 | — | 0.00 | Nov 9, 2023 | Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. | |||
| CVE-2023-5542 | 0.00 | — | 0.00 | Nov 9, 2023 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. | |||
| CVE-2023-47110 | 0.00 | — | 0.00 | Nov 9, 2023 | blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in… | |||
| CVE-2023-5976 | 0.00 | — | 0.00 | Nov 7, 2023 | Improper Access Control in GitHub repository microweber/microweber prior to 2.0. | |||
| CVE-2023-44794 | — | 0.00 | — | 0.02 | Oct 25, 2023 | An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. | ||
| CVE-2023-41882 | 0.00 | — | 0.00 | Oct 11, 2023 | vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However,… | |||
| CVE-2023-36820 | 0.00 | — | 0.00 | Oct 9, 2023 | Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC… | |||
| CVE-2023-36465 | 0.00 | — | 0.00 | Oct 6, 2023 | Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to… |
- CVE-2023-51661Dec 22, 2023risk 0.00cvss —epss 0.00
Wasmer is a WebAssembly runtime that enables containers to run anywhere: from Desktop to the Cloud, Edge and even the browser. Wasm programs can access the filesystem outside of the sandbox. Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host…
- CVE-2023-50783Dec 21, 2023risk 0.00cvss —epss 0.00
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.…
- CVE-2023-47327Dec 13, 2023risk 0.00cvss —epss 0.00
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
- CVE-2023-47321Dec 13, 2023risk 0.00cvss —epss 0.00
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.
- CVE-2023-47320Dec 13, 2023risk 0.00cvss —epss 0.00
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users.…
- CVE-2023-47325Dec 13, 2023risk 0.00cvss —epss 0.00
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
- CVE-2023-32065Nov 28, 2023risk 0.00cvss —epss 0.00
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.
- CVE-2023-32064Nov 28, 2023risk 0.00cvss —epss 0.00
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in…
- CVE-2023-32063Nov 28, 2023risk 0.00cvss —epss 0.00
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and…
- CVE-2023-32062Nov 27, 2023risk 0.00cvss —epss 0.00
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
- CVE-2023-6202Nov 27, 2023risk 0.00cvss —epss 0.00
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
- CVE-2023-47865Nov 27, 2023risk 0.00cvss —epss 0.00
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a…
- CVE-2023-5549Nov 9, 2023risk 0.00cvss —epss 0.00
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
- CVE-2023-5542Nov 9, 2023risk 0.00cvss —epss 0.00
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
- CVE-2023-47110Nov 9, 2023risk 0.00cvss —epss 0.00
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in…
- CVE-2023-5976Nov 7, 2023risk 0.00cvss —epss 0.00
Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
- CVE-2023-44794Oct 25, 2023risk 0.00cvss —epss 0.02
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
- CVE-2023-41882Oct 11, 2023risk 0.00cvss —epss 0.00
vantage6 is privacy preserving federated learning infrastructure. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However,…
- CVE-2023-36820Oct 9, 2023risk 0.00cvss —epss 0.00
Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC…
- CVE-2023-36465Oct 6, 2023risk 0.00cvss —epss 0.00
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to…