VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 81 of 82
  • CVE-2022-0821MedMar 11, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

  • CVE-2022-0829HigMar 2, 2022
    risk 0.00cvss 8.1epss 0.01

    Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2021-3837MedJan 3, 2022
    risk 0.00cvss 6.1epss 0.01

    openwhyd is vulnerable to Improper Authorization

  • CVE-2021-43847MedDec 20, 2021
    risk 0.00cvss 6.5epss 0.01

    HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.

  • CVE-2021-41137HigOct 13, 2021
    risk 0.00cvss 8.8epss 0.01

    Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restrictions on regular users. Normally, checkKeyValid() should return owner true for rootCreds. In the…

  • CVE-2021-41093HigOct 4, 2021
    risk 0.00cvss 7.4epss 0.01

    Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by changing the email. This issue has been resolved in version 3.86 which uses a new endpoint which additionally requires an…

  • CVE-2021-32688HigJul 12, 2021
    risk 0.00cvss 8.8epss 0.02

    Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the…

  • CVE-2021-21362HigMar 8, 2021
    risk 0.00cvss 7.7epss 0.01

    MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a temporary 'mc share upload' URL. Everyone…

  • CVE-2020-26246HigDec 3, 2020
    risk 0.00cvss 7.7epss 0.01

    Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.

  • CVE-2020-2234MedAug 12, 2020
    risk 0.00cvss 6.5epss 0.01

    A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing…

  • CVE-2020-2233MedAug 12, 2020
    risk 0.00cvss 6.5epss 0.01

    A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2020-2197MedJun 3, 2020
    risk 0.00cvss 4.3epss 0.01

    Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.

  • CVE-2020-5289MedMar 30, 2020
    risk 0.00cvss 6.8epss 0.01

    In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions for an inaccessible field to filter a…

  • CVE-2020-5250HigMar 5, 2020
    risk 0.00cvss 7.6epss 0.01

    In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change all information of all…

  • CVE-2020-2118MedFeb 12, 2020
    risk 0.00cvss 4.3epss 0.01

    A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2020-2117MedFeb 12, 2020
    risk 0.00cvss 4.3epss 0.01

    A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored…

  • CVE-2018-12467MedAug 1, 2018
    risk 0.00cvss 6.0epss 0.01

    Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.

  • CVE-2018-12466MedAug 1, 2018
    risk 0.00cvss 4.4epss 0.01

    openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.

  • CVE-2018-1116MedJul 10, 2018
    risk 0.00cvss 4.4epss 0.01

    A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a…

  • CVE-2018-10861HigJul 10, 2018
    risk 0.00cvss 8.1epss 0.03

    A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.