VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,748)

page 76 of 88
  • CVE-2023-47037MedNov 12, 2023
    risk 0.21cvss 4.3epss 0.01

    We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting…

  • CVE-2023-3957MedJul 27, 2023
    risk 0.21cvss 4.3epss 0.01

    The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with…

  • CVE-2023-0583MedJun 3, 2023
    risk 0.21cvss 4.3epss 0.01

    The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings…

  • CVE-2022-40208MedMar 24, 2023
    risk 0.21cvss 4.3epss 0.01

    In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.

  • CVE-2023-21452LowMar 16, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.

  • CVE-2023-21436LowFeb 9, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.

  • CVE-2023-0610MedFeb 1, 2023
    risk 0.21cvss 4.3epss 0.00

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

  • CVE-2023-0609MedFeb 1, 2023
    risk 0.21cvss 4.3epss 0.01

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

  • CVE-2022-4868MedDec 31, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

  • CVE-2022-33705LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.

  • CVE-2021-25354LowMar 25, 2021
    risk 0.21cvss 3.3epss 0.00

    Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.

  • CVE-2021-25351LowMar 25, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

  • CVE-2020-2202MedJul 2, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2020-2191MedJun 3, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels.

  • CVE-2020-2148MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2020-2104MedJan 29, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.

  • CVE-2019-16547MedNov 21, 2019
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited information about the plugin configuration and environment.

  • CVE-2019-10439MedOct 16, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2019-10357MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.

  • CVE-2019-10344MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.