VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 30 of 34
  • CVE-2021-21492MedApr 13, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

  • CVE-2020-4864MedOct 29, 2020
    risk 0.28cvss 4.3epss 0.00

    IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address. IBM X-Force ID: 190567.

  • CVE-2020-6810MedMar 25, 2020
    risk 0.28cvss 4.3epss 0.01

    After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin…

  • CVE-2019-13715MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2019-13708MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2019-13704MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2019-13703MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2019-13701MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2019-1357MedOct 10, 2019
    risk 0.28cvss 4.3epss 0.02

    A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.

  • CVE-2019-0608MedOct 10, 2019
    risk 0.28cvss 4.3epss 0.02

    A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.

  • CVE-2018-8425MedSep 13, 2018
    risk 0.28cvss 4.3epss 0.03

    A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.

  • CVE-2018-8388MedAug 15, 2018
    risk 0.28cvss 4.3epss 0.04

    A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8383.

  • CVE-2018-8383MedAug 15, 2018
    risk 0.28cvss 4.3epss 0.06

    A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8388.

  • CVE-2026-45045MedJul 8, 2026
    risk 0.27cvss 5.3epss 0.00

    Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be…

  • CVE-2026-24000MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their apparent IP address and bypass…

  • CVE-2026-28471MedMar 5, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver validation. Remote Matrix users…

  • CVE-2025-56608MedSep 3, 2025
    risk 0.27cvss 4.2epss 0.00

    The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cryptographic algorithm…

  • CVE-2025-22223MedMar 24, 2025
    risk 0.27cvss 5.3epss 0.00

    Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.  You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on…

  • CVE-2024-49214MedOct 14, 2024
    risk 0.27cvss 5.3epss 0.01

    QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.

  • CVE-2023-44463MedOct 2, 2023
    risk 0.27cvss 5.3epss 0.01

    An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.