CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (6,523)
page 314 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25093 | Med | 0.00 | 5.5 | 0.00 | Nov 6, 2023 | A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to… | ||
| CVE-2018-25092 | Med | 0.00 | 5.5 | 0.00 | Nov 5, 2023 | A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version… | ||
| CVE-2023-5833 | Hig | 0.00 | 8.8 | 0.01 | Oct 30, 2023 | Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. | ||
| CVE-2023-5353 | Med | 0.00 | 6.5 | 0.01 | Oct 3, 2023 | Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2023-4650 | Med | 0.00 | 4.7 | 0.00 | Aug 31, 2023 | Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-39963 | Hig | 0.00 | 8.1 | 0.00 | Aug 10, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prior to versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a missing password confirmation allowed an attacker, after… | ||
| CVE-2023-39962 | Hig | 0.00 | 7.7 | 0.01 | Aug 10, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prior to versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a malicious user could delete any personal or… | ||
| CVE-2023-39961 | Low | 0.00 | 3.5 | 0.01 | Aug 10, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions, the user could add the image inline… | ||
| CVE-2023-39959 | Low | 0.00 | 3.5 | 0.01 | Aug 10, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.9, 26.0.4, and 27.0.1, unauthenticated users could send a DAV request which reveals whether a calendar or an address book with the given… | ||
| CVE-2023-39952 | Med | 0.00 | 6.5 | 0.01 | Aug 10, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1, a user can access files inside a subfolder of a groupfolder accessible to them,… | ||
| CVE-2023-35927 | Hig | 0.00 | 7.6 | 0.01 | Jun 23, 2023 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until… | ||
| CVE-2023-35173 | Med | 0.00 | 5.7 | 0.00 | Jun 23, 2023 | Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end… | ||
| CVE-2023-2946 | Hig | 0.00 | 8.1 | 0.00 | May 27, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2944 | Med | 0.00 | 5.4 | 0.00 | May 27, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-2845 | Hig | 0.00 | 8.1 | 0.01 | May 23, 2023 | Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | ||
| CVE-2023-2674 | Med | 0.00 | 4.3 | 0.01 | May 12, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-30539 | Med | 0.00 | 6.5 | 0.01 | Apr 17, 2023 | Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that… | ||
| CVE-2023-28845 | Low | 0.00 | 3.5 | 0.00 | Mar 31, 2023 | Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation,… | ||
| CVE-2023-28844 | Med | 0.00 | 5.7 | 0.01 | Mar 31, 2023 | Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users… | ||
| CVE-2023-28645 | Med | 0.00 | 5.7 | 0.01 | Mar 31, 2023 | Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the… |
- risk 0.00cvss 5.5epss 0.00
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to…
- risk 0.00cvss 5.5epss 0.00
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version…
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
- risk 0.00cvss 6.5epss 0.01
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.00cvss 4.7epss 0.00
Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 8.1epss 0.00
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prior to versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a missing password confirmation allowed an attacker, after…
- risk 0.00cvss 7.7epss 0.01
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prior to versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a malicious user could delete any personal or…
- risk 0.00cvss 3.5epss 0.01
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions, the user could add the image inline…
- risk 0.00cvss 3.5epss 0.01
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.9, 26.0.4, and 27.0.1, unauthenticated users could send a DAV request which reveals whether a calendar or an address book with the given…
- risk 0.00cvss 6.5epss 0.01
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1, a user can access files inside a subfolder of a groupfolder accessible to them,…
- risk 0.00cvss 7.6epss 0.01
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until…
- risk 0.00cvss 5.7epss 0.00
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end…
- risk 0.00cvss 8.1epss 0.00
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 5.4epss 0.00
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 8.1epss 0.01
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
- risk 0.00cvss 4.3epss 0.01
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 6.5epss 0.01
Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that…
- risk 0.00cvss 3.5epss 0.00
Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation,…
- risk 0.00cvss 5.7epss 0.01
Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users…
- risk 0.00cvss 5.7epss 0.01
Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the…