CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (6,523)
page 315 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1647 | Hig | 0.00 | 8.8 | 0.01 | Mar 27, 2023 | Improper Access Control in GitHub repository calcom/cal.com prior to 2.7. | ||
| CVE-2023-25821 | Med | 0.00 | 5.7 | 0.01 | Feb 25, 2023 | Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissions are also given. This issue is… | ||
| CVE-2023-23923 | Hig | 0.00 | 8.2 | 0.01 | Feb 17, 2023 | The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted… | ||
| CVE-2023-25149 | Hig | 0.00 | 8.8 | 0.01 | Feb 14, 2023 | TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run as part of the telemetry data… | ||
| CVE-2023-25161 | Low | 0.00 | 3.7 | 0.01 | Feb 13, 2023 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service… | ||
| CVE-2023-25159 | Low | 0.00 | 2.3 | 0.00 | Feb 13, 2023 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud Enterprise Server 24.0.x… | ||
| CVE-2023-25150 | Med | 0.00 | 5.8 | 0.01 | Feb 8, 2023 | Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the… | ||
| CVE-2023-24028 | Cri | 0.00 | 9.8 | 0.01 | Jan 20, 2023 | In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function. | ||
| CVE-2023-22903 | Cri | 0.00 | 9.8 | 0.01 | Jan 10, 2023 | api/views/user.py in LibrePhotos before e19e539 has incorrect access control. | ||
| CVE-2023-22473 | Low | 0.00 | 2.1 | 0.01 | Jan 9, 2023 | Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There… | ||
| CVE-2022-23508 | Hig | 0.00 | 8.8 | 0.00 | Jan 9, 2023 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3… | ||
| CVE-2021-4300 | Med | 0.00 | 6.3 | 0.01 | Jan 4, 2023 | A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIndex of the file src/main.cpp of the component Block Verification. The manipulation leads to improper access controls. The attack… | ||
| CVE-2022-4567 | Hig | 0.00 | 8.1 | 0.01 | Dec 17, 2022 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-41970 | Low | 0.00 | 2.6 | 0.01 | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.… | ||
| CVE-2022-4087 | Low | 0.00 | 2.6 | 0.00 | Nov 21, 2022 | A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name… | ||
| CVE-2022-39329 | Low | 0.00 | 3.5 | 0.01 | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without… | ||
| CVE-2022-39310 | Med | 0.00 | 4.9 | 0.01 | Oct 14, 2022 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 can allow one authenticated agent to impersonate another agent, and thus receive work packages for… | ||
| CVE-2022-42717 | Hig | 0.00 | 7.8 | 0.00 | Oct 11, 2022 | An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers… | ||
| CVE-2022-36088 | Med | 0.00 | 5.0 | 0.00 | Sep 7, 2022 | GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local access to the… | ||
| CVE-2022-3065 | Hig | 0.00 | 7.5 | 0.01 | Sep 2, 2022 | Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8. |
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository calcom/cal.com prior to 2.7.
- risk 0.00cvss 5.7epss 0.01
Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissions are also given. This issue is…
- risk 0.00cvss 8.2epss 0.01
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted…
- risk 0.00cvss 8.8epss 0.01
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run as part of the telemetry data…
- risk 0.00cvss 3.7epss 0.01
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service…
- risk 0.00cvss 2.3epss 0.00
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud Enterprise Server 24.0.x…
- risk 0.00cvss 5.8epss 0.01
Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the…
- risk 0.00cvss 9.8epss 0.01
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
- risk 0.00cvss 9.8epss 0.01
api/views/user.py in LibrePhotos before e19e539 has incorrect access control.
- risk 0.00cvss 2.1epss 0.01
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There…
- risk 0.00cvss 8.8epss 0.00
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3…
- risk 0.00cvss 6.3epss 0.01
A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIndex of the file src/main.cpp of the component Block Verification. The manipulation leads to improper access controls. The attack…
- risk 0.00cvss 8.1epss 0.01
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 2.6epss 0.01
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.…
- risk 0.00cvss 2.6epss 0.00
A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name…
- risk 0.00cvss 3.5epss 0.01
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without…
- risk 0.00cvss 4.9epss 0.01
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 can allow one authenticated agent to impersonate another agent, and thus receive work packages for…
- risk 0.00cvss 7.8epss 0.00
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers…
- risk 0.00cvss 5.0epss 0.00
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local access to the…
- risk 0.00cvss 7.5epss 0.01
Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.