CWE-285
Improper Authorization
Description
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87
CVEs mapped to this weakness (1,626)
page 80 of 82| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-36399 | Hig | 0.00 | 8.2 | 0.00 | Jun 6, 2024 | Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is… | ||
| CVE-2024-27930 | Med | 0.00 | 6.5 | 0.01 | Mar 18, 2024 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version… | ||
| CVE-2023-52139 | Cri | 0.00 | 9.0 | 0.01 | Dec 29, 2023 | Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/b… | ||
| CVE-2023-5948 | Med | 0.00 | 5.5 | 0.00 | Nov 3, 2023 | Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91. | ||
| CVE-2023-33183 | Low | 0.00 | 2.6 | 0.00 | May 30, 2023 | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3 | ||
| CVE-2023-2950 | Hig | 0.00 | 8.1 | 0.01 | May 28, 2023 | Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-28623 | Med | 0.00 | 6.5 | 0.01 | May 19, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabled in… | ||
| CVE-2022-4879 | Med | 0.00 | 4.6 | 0.01 | Jan 6, 2023 | A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to… | ||
| CVE-2022-23542 | Hig | 0.00 | 7.7 | 0.01 | Dec 20, 2022 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in… | ||
| CVE-2022-39356 | Hig | 0.00 | 8.9 | 0.01 | Nov 2, 2022 | Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest… | ||
| CVE-2022-39329 | Low | 0.00 | 3.5 | 0.01 | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without… | ||
| CVE-2022-2901 | Hig | 0.00 | 7.1 | 0.01 | Sep 6, 2022 | Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8. | ||
| CVE-2022-2595 | Cri | 0.00 | 10.0 | 0.01 | Aug 1, 2022 | Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. | ||
| CVE-2022-31168 | Med | 0.00 | 5.4 | 0.01 | Jul 22, 2022 | Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server… | ||
| CVE-2022-31025 | Low | 0.00 | 2.6 | 0.01 | Jun 7, 2022 | Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_approve_users` check and invites by staff… | ||
| CVE-2022-29236 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a… | ||
| CVE-2022-29234 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a… | ||
| CVE-2022-29233 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of… | ||
| CVE-2022-1224 | Med | 0.00 | 6.5 | 0.01 | Apr 4, 2022 | Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | ||
| CVE-2022-0406 | Med | 0.00 | 4.3 | 0.01 | Apr 3, 2022 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. |
- risk 0.00cvss 8.2epss 0.00
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is…
- risk 0.00cvss 6.5epss 0.01
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version…
- risk 0.00cvss 9.0epss 0.01
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/b…
- risk 0.00cvss 5.5epss 0.00
Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.
- risk 0.00cvss 2.6epss 0.00
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3
- risk 0.00cvss 8.1epss 0.01
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 6.5epss 0.01
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabled in…
- risk 0.00cvss 4.6epss 0.01
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to…
- risk 0.00cvss 7.7epss 0.01
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in…
- risk 0.00cvss 8.9epss 0.01
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest…
- risk 0.00cvss 3.5epss 0.01
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without…
- risk 0.00cvss 7.1epss 0.01
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
- risk 0.00cvss 10.0epss 0.01
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
- risk 0.00cvss 5.4epss 0.01
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server…
- risk 0.00cvss 2.6epss 0.01
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_approve_users` check and invites by staff…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of…
- risk 0.00cvss 6.5epss 0.01
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- risk 0.00cvss 4.3epss 0.01
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.