CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (6,523)
page 316 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3019 | Hig | 0.00 | 8.8 | 0.01 | Aug 29, 2022 | The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one). | ||
| CVE-2022-2631 | Hig | 0.00 | 8.8 | 0.01 | Aug 2, 2022 | Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0. | ||
| CVE-2022-31055 | Hig | 0.00 | 7.5 | 0.01 | Jun 13, 2022 | kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who want to test challenges… | ||
| CVE-2022-31024 | Med | 0.00 | 6.5 | 0.01 | Jun 2, 2022 | richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and… | ||
| CVE-2022-29160 | Low | 0.00 | 2.8 | 0.00 | May 20, 2022 | Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information.… | ||
| CVE-2019-25060 | Med | 0.00 | 5.3 | 0.02 | May 9, 2022 | The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site. | ||
| CVE-2022-24841 | Med | 0.00 | 6.5 | 0.01 | Apr 18, 2022 | fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In… | ||
| CVE-2022-0405 | Med | 0.00 | 4.3 | 0.01 | Apr 3, 2022 | Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16. | ||
| CVE-2021-3967 | Hig | 0.00 | 8.8 | 0.01 | Feb 26, 2022 | Improper Access Control in GitHub repository zulip/zulip prior to 4.10. | ||
| CVE-2022-21706 | Hig | 0.00 | 7.2 | 0.01 | Feb 26, 2022 | Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack… | ||
| CVE-2022-0727 | Med | 0.00 | 5.4 | 0.01 | Feb 23, 2022 | Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0. | ||
| CVE-2022-0170 | Med | 0.00 | 4.3 | 0.01 | Jan 11, 2022 | peertube is vulnerable to Improper Access Control | ||
| CVE-2022-0133 | Hig | 0.00 | 7.5 | 0.01 | Jan 10, 2022 | peertube is vulnerable to Improper Access Control | ||
| CVE-2021-22567 | Med | 0.00 | 4.6 | 0.01 | Jan 5, 2022 | Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the… | ||
| CVE-2021-25991 | Med | 0.00 | 5.7 | 0.01 | Dec 29, 2021 | In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme. | ||
| CVE-2021-43996 | Cri | 0.00 | 9.8 | 0.02 | Nov 17, 2021 | The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control. | ||
| CVE-2021-3626 | Hig | 0.00 | 8.8 | 0.00 | Oct 1, 2021 | The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation. | ||
| CVE-2021-40347 | Med | 0.00 | 5.4 | 0.01 | Sep 10, 2021 | An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place. | ||
| CVE-2019-10200 | Hig | 0.00 | 7.2 | 0.01 | Mar 19, 2021 | A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials… | ||
| CVE-2021-22877 | Med | 0.00 | 6.5 | 0.02 | Mar 3, 2021 | A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet. |
- risk 0.00cvss 8.8epss 0.01
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
- risk 0.00cvss 7.5epss 0.01
kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who want to test challenges…
- risk 0.00cvss 6.5epss 0.01
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and…
- risk 0.00cvss 2.8epss 0.00
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information.…
- risk 0.00cvss 5.3epss 0.02
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
- risk 0.00cvss 6.5epss 0.01
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In…
- risk 0.00cvss 4.3epss 0.01
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
- risk 0.00cvss 7.2epss 0.01
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…
- risk 0.00cvss 5.4epss 0.01
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
- risk 0.00cvss 4.3epss 0.01
peertube is vulnerable to Improper Access Control
- risk 0.00cvss 7.5epss 0.01
peertube is vulnerable to Improper Access Control
- risk 0.00cvss 4.6epss 0.01
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the…
- risk 0.00cvss 5.7epss 0.01
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
- risk 0.00cvss 9.8epss 0.02
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.
- risk 0.00cvss 8.8epss 0.00
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.
- risk 0.00cvss 5.4epss 0.01
An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.
- risk 0.00cvss 7.2epss 0.01
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials…
- risk 0.00cvss 6.5epss 0.02
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.