CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (2,580)
page 112 of 129| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36036 | 0.00 | — | 0.02 | Sep 6, 2023 | Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker… | |||
| CVE-2023-4696 | — | 0.00 | — | 0.01 | Sep 1, 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2023-40170 | 0.00 | — | 0.01 | Aug 28, 2023 | jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in… | |||
| CVE-2023-40579 | 0.00 | — | 0.00 | Aug 25, 2023 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with… | |||
| CVE-2023-40573 | 0.00 | — | 0.04 | Aug 24, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job… | |||
| CVE-2023-36106 | 0.00 | — | 0.00 | Aug 17, 2023 | An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list. | |||
| CVE-2023-4107 | 0.00 | — | 0.00 | Aug 11, 2023 | Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name. | |||
| CVE-2023-4106 | 0.00 | — | 0.00 | Aug 11, 2023 | Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks. | |||
| CVE-2023-4105 | 0.00 | — | 0.00 | Aug 11, 2023 | Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message | |||
| CVE-2023-4304 | 0.00 | — | 0.00 | Aug 11, 2023 | Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0. | |||
| CVE-2023-39349 | 0.00 | — | 0.00 | Aug 7, 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with… | |||
| CVE-2023-37478 | 0.00 | — | 0.02 | Aug 1, 2023 | pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or… | |||
| CVE-2023-3700 | — | 0.00 | — | 0.00 | Jul 17, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||
| CVE-2023-37267 | 0.00 | — | 0.00 | Jul 13, 2023 | Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1. | |||
| CVE-2023-3431 | 0.00 | — | 0.00 | Jun 27, 2023 | Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. | |||
| CVE-2023-35167 | 0.00 | — | 0.00 | Jun 23, 2023 | Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attacker who knows the `id` of an entity instance is not… | |||
| CVE-2023-3304 | 0.00 | — | 0.00 | Jun 23, 2023 | Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9. | |||
| CVE-2023-3303 | 0.00 | — | 0.00 | Jun 23, 2023 | Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9. | |||
| CVE-2023-2183 | 0.00 | — | 0.01 | Jun 6, 2023 | Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API… | |||
| CVE-2023-3095 | 0.00 | — | 0.00 | Jun 4, 2023 | Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
- CVE-2021-36036Sep 6, 2023risk 0.00cvss —epss 0.02
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker…
- CVE-2023-4696Sep 1, 2023risk 0.00cvss —epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- CVE-2023-40170Aug 28, 2023risk 0.00cvss —epss 0.01
jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in…
- CVE-2023-40579Aug 25, 2023risk 0.00cvss —epss 0.00
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with…
- CVE-2023-40573Aug 24, 2023risk 0.00cvss —epss 0.04
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job…
- CVE-2023-36106Aug 17, 2023risk 0.00cvss —epss 0.00
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.
- CVE-2023-4107Aug 11, 2023risk 0.00cvss —epss 0.00
Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.
- CVE-2023-4106Aug 11, 2023risk 0.00cvss —epss 0.00
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
- CVE-2023-4105Aug 11, 2023risk 0.00cvss —epss 0.00
Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message
- CVE-2023-4304Aug 11, 2023risk 0.00cvss —epss 0.00
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
- CVE-2023-39349Aug 7, 2023risk 0.00cvss —epss 0.00
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with…
- CVE-2023-37478Aug 1, 2023risk 0.00cvss —epss 0.02
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or…
- CVE-2023-3700Jul 17, 2023risk 0.00cvss —epss 0.00
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- CVE-2023-37267Jul 13, 2023risk 0.00cvss —epss 0.00
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.
- CVE-2023-3431Jun 27, 2023risk 0.00cvss —epss 0.00
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
- CVE-2023-35167Jun 23, 2023risk 0.00cvss —epss 0.00
Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attacker who knows the `id` of an entity instance is not…
- CVE-2023-3304Jun 23, 2023risk 0.00cvss —epss 0.00
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
- CVE-2023-3303Jun 23, 2023risk 0.00cvss —epss 0.00
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.
- CVE-2023-2183Jun 6, 2023risk 0.00cvss —epss 0.01
Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API…
- CVE-2023-3095Jun 4, 2023risk 0.00cvss —epss 0.00
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.