CWE-285
Improper Authorization
Description
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87
CVEs mapped to this weakness (1,748)
page 76 of 88| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47037 | Med | 0.21 | 4.3 | 0.01 | Nov 12, 2023 | We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting… | ||
| CVE-2023-3957 | Med | 0.21 | 4.3 | 0.01 | Jul 27, 2023 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with… | ||
| CVE-2023-0583 | Med | 0.21 | 4.3 | 0.01 | Jun 3, 2023 | The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings… | ||
| CVE-2022-40208 | Med | 0.21 | 4.3 | 0.01 | Mar 24, 2023 | In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt. | ||
| CVE-2023-21452 | Low | 0.21 | 3.3 | 0.00 | Mar 16, 2023 | Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device. | ||
| CVE-2023-21436 | Low | 0.21 | 3.3 | 0.00 | Feb 9, 2023 | Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID. | ||
| CVE-2023-0610 | Med | 0.21 | 4.3 | 0.00 | Feb 1, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. | ||
| CVE-2023-0609 | Med | 0.21 | 4.3 | 0.01 | Feb 1, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. | ||
| CVE-2022-4868 | Med | 0.21 | 4.3 | 0.01 | Dec 31, 2022 | Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||
| CVE-2022-33705 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission. | ||
| CVE-2021-25354 | Low | 0.21 | 3.3 | 0.00 | Mar 25, 2021 | Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink. | ||
| CVE-2021-25351 | Low | 0.21 | 3.2 | 0.00 | Mar 25, 2021 | Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password. | ||
| CVE-2020-2202 | Med | 0.21 | 4.3 | 0.01 | Jul 2, 2020 | A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | ||
| CVE-2020-2191 | Med | 0.21 | 4.3 | 0.01 | Jun 3, 2020 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels. | ||
| CVE-2020-2148 | Med | 0.21 | 4.3 | 0.01 | Mar 9, 2020 | A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials. | ||
| CVE-2020-2104 | Med | 0.21 | 4.3 | 0.01 | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart. | ||
| CVE-2019-16547 | Med | 0.21 | 4.3 | 0.01 | Nov 21, 2019 | Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited information about the plugin configuration and environment. | ||
| CVE-2019-10439 | Med | 0.21 | 4.3 | 0.01 | Oct 16, 2019 | A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | ||
| CVE-2019-10357 | Med | 0.21 | 4.3 | 0.01 | Jul 31, 2019 | A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries. | ||
| CVE-2019-10344 | Med | 0.21 | 4.3 | 0.01 | Jul 31, 2019 | Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins. |
- risk 0.21cvss 4.3epss 0.01
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting…
- risk 0.21cvss 4.3epss 0.01
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with…
- risk 0.21cvss 4.3epss 0.01
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings…
- risk 0.21cvss 4.3epss 0.01
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
- risk 0.21cvss 3.3epss 0.00
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
- risk 0.21cvss 3.3epss 0.00
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
- risk 0.21cvss 4.3epss 0.00
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
- risk 0.21cvss 4.3epss 0.01
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
- risk 0.21cvss 4.3epss 0.01
Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
- risk 0.21cvss 3.3epss 0.00
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.
- risk 0.21cvss 3.3epss 0.00
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.
- risk 0.21cvss 3.2epss 0.00
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
- risk 0.21cvss 4.3epss 0.01
A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
- risk 0.21cvss 4.3epss 0.01
Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels.
- risk 0.21cvss 4.3epss 0.01
A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.
- risk 0.21cvss 4.3epss 0.01
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
- risk 0.21cvss 4.3epss 0.01
Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited information about the plugin configuration and environment.
- risk 0.21cvss 4.3epss 0.01
A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
- risk 0.21cvss 4.3epss 0.01
A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.
- risk 0.21cvss 4.3epss 0.01
Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.