VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 70 of 82
  • CVE-2023-0609MedFeb 1, 2023
    risk 0.21cvss 4.3epss 0.01

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

  • CVE-2022-4868MedDec 31, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

  • CVE-2022-33705LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.

  • CVE-2021-25354LowMar 25, 2021
    risk 0.21cvss 3.3epss 0.00

    Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.

  • CVE-2021-25351LowMar 25, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

  • CVE-2020-2202MedJul 2, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2020-2191MedJun 3, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels.

  • CVE-2020-2148MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2020-2104MedJan 29, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.

  • CVE-2019-16547MedNov 21, 2019
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited information about the plugin configuration and environment.

  • CVE-2019-10439MedOct 16, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2019-10357MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.

  • CVE-2019-10344MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.

  • CVE-2016-7078MedSep 10, 2018
    risk 0.21cvss 4.3epss 0.01

    foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are…

  • CVE-2016-7077MedSep 10, 2018
    risk 0.21cvss 4.3epss 0.01

    foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.

  • CVE-2026-4958LowMar 27, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/websockets/replayer.py of the component WebSocket Endpoint. Such manipulation of the argument interaction_id…

  • CVE-2026-4549LowMar 22, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack…

  • CVE-2025-15126LowDec 28, 2025
    risk 0.20cvss 3.1epss 0.00

    A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The attack may be initiated…

  • CVE-2025-15125LowDec 28, 2025
    risk 0.20cvss 3.1epss 0.00

    A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in improper authorization. The attack can be launched remotely. This…

  • CVE-2025-15124LowDec 28, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be initiated remotely. The attack's complexity…