VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 205 of 241
  • CVE-2021-21378HigMar 11, 2021
    risk 0.00cvss 8.2epss 0.02

    Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the…

  • CVE-2021-21335MedMar 8, 2021
    risk 0.00cvss 5.3epss 0.02

    In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in…

  • CVE-2021-21329HigMar 8, 2021
    risk 0.00cvss 8.7epss 0.01

    RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF users with multi factor authentication enabled are able to log in without a valid token. This is fixed in commit cebb67b.

  • CVE-2021-21308MedFeb 26, 2021
    risk 0.00cvss 6.1epss 0.01

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2

  • CVE-2020-29668LowDec 10, 2020
    risk 0.00cvss 3.7epss 0.02

    Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

  • CVE-2020-28896MedNov 23, 2020
    risk 0.00cvss 5.3epss 0.02

    Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in…

  • CVE-2020-26236HigNov 20, 2020
    risk 0.00cvss 7.5epss 0.01

    In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's account on any site that uses ScratchVerifier for logins. A possible exploitation would follow these steps: 1. User starts login process. 2. Attacker attempts…

  • CVE-2020-15164CriAug 28, 2020
    risk 0.00cvss 10.0epss 0.01

    in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by MediaWiki. This affects all users on any wiki using this…

  • CVE-2020-24612MedAug 24, 2020
    risk 0.00cvss 6.7epss 0.00

    An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If…

  • CVE-2020-15149CriAug 20, 2020
    risk 0.00cvss 9.9epss 0.02

    NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation…

  • CVE-2020-16088CriJul 28, 2020
    risk 0.00cvss 9.8epss 0.02

    iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.

  • CVE-2019-15299HigFeb 24, 2020
    risk 0.00cvss 8.8epss 0.02

    An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.

  • CVE-2018-20954HigAug 8, 2019
    risk 0.00cvss 7.5epss 0.01

    The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys.

  • CVE-2019-1020018HigJul 29, 2019
    risk 0.00cvss 7.3epss 0.01

    Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.

  • CVE-2019-12530CriJun 2, 2019
    risk 0.00cvss 9.8epss 0.02

    Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.

  • CVE-2019-12395MedMay 28, 2019
    risk 0.00cvss 5.3epss 0.02

    In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.

  • CVE-2019-11576CriApr 28, 2019
    risk 0.00cvss 9.8epss 0.02

    Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.

  • CVE-2018-16877HigApr 18, 2019
    risk 0.00cvss 7.8epss 0.00

    A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.

  • CVE-2019-3878HigMar 26, 2019
    risk 0.00cvss 8.1epss 0.03

    A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start…

  • CVE-2018-19937MedDec 31, 2018
    risk 0.00cvss 6.6epss 0.00

    A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.