VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,748)

page 68 of 88
  • CVE-2022-4798MedDec 28, 2022
    risk 0.28cvss 5.3epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-39340MedOct 25, 2022
    risk 0.28cvss 5.3epss 0.01

    OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA…

  • CVE-2022-39873MedOct 7, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.

  • CVE-2022-32170MedSep 28, 2022
    risk 0.28cvss 4.3epss 0.01

    The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.

  • CVE-2022-32169MedSep 28, 2022
    risk 0.28cvss 4.3epss 0.01

    The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.

  • CVE-2022-0027MedMay 11, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the…

  • CVE-2021-42337MedNov 16, 2021
    risk 0.28cvss 4.3epss 0.01

    The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.

  • CVE-2021-41313MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are…

  • CVE-2021-42336MedOct 15, 2021
    risk 0.28cvss 4.3epss 0.01

    The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters.

  • CVE-2021-42332MedOct 15, 2021
    risk 0.28cvss 4.3epss 0.01

    The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other users’ message boards by crafting URL parameters.

  • CVE-2019-14828MedMar 19, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be…

  • CVE-2021-21026MedFeb 11, 2021
    risk 0.28cvss 5.3epss 0.02

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the integrations module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated…

  • CVE-2020-24405MedNov 9, 2020
    risk 0.28cvss 4.3epss 0.02

    Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inventory module. This vulnerability could be abused by authenticated users to modify inventory stock data without authorization.

  • CVE-2020-10517MedAug 27, 2020
    risk 0.28cvss 4.3epss 0.01

    An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any…

  • CVE-2020-2216MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified username and password.

  • CVE-2020-2204MedJul 2, 2020
    risk 0.28cvss 5.4epss 0.01

    A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.

  • CVE-2020-2188MedMay 6, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2020-5333MedMay 4, 2020
    risk 0.28cvss 4.3epss 0.01

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.

  • CVE-2020-8119MedFeb 4, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.

  • CVE-2019-15610MedFeb 4, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.