VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 316 of 327
  • CVE-2022-3019HigAug 29, 2022
    risk 0.00cvss 8.8epss 0.01

    The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).

  • CVE-2022-2631HigAug 2, 2022
    risk 0.00cvss 8.8epss 0.01

    Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

  • CVE-2022-31055HigJun 13, 2022
    risk 0.00cvss 7.5epss 0.01

    kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who want to test challenges…

  • CVE-2022-31024MedJun 2, 2022
    risk 0.00cvss 6.5epss 0.01

    richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and…

  • CVE-2022-29160LowMay 20, 2022
    risk 0.00cvss 2.8epss 0.00

    Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information.…

  • CVE-2019-25060MedMay 9, 2022
    risk 0.00cvss 5.3epss 0.02

    The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

  • CVE-2022-24841MedApr 18, 2022
    risk 0.00cvss 6.5epss 0.01

    fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In…

  • CVE-2022-0405MedApr 3, 2022
    risk 0.00cvss 4.3epss 0.01

    Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.

  • CVE-2021-3967HigFeb 26, 2022
    risk 0.00cvss 8.8epss 0.01

    Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

  • CVE-2022-21706HigFeb 26, 2022
    risk 0.00cvss 7.2epss 0.01

    Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…

  • CVE-2022-0727MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-0170MedJan 11, 2022
    risk 0.00cvss 4.3epss 0.01

    peertube is vulnerable to Improper Access Control

  • CVE-2022-0133HigJan 10, 2022
    risk 0.00cvss 7.5epss 0.01

    peertube is vulnerable to Improper Access Control

  • CVE-2021-22567MedJan 5, 2022
    risk 0.00cvss 4.6epss 0.01

    Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the…

  • CVE-2021-25991MedDec 29, 2021
    risk 0.00cvss 5.7epss 0.01

    In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

  • CVE-2021-43996CriNov 17, 2021
    risk 0.00cvss 9.8epss 0.02

    The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.

  • CVE-2021-3626HigOct 1, 2021
    risk 0.00cvss 8.8epss 0.00

    The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.

  • CVE-2021-40347MedSep 10, 2021
    risk 0.00cvss 5.4epss 0.01

    An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

  • CVE-2019-10200HigMar 19, 2021
    risk 0.00cvss 7.2epss 0.01

    A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials…

  • CVE-2021-22877MedMar 3, 2021
    risk 0.00cvss 6.5epss 0.02

    A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.