VYPR

CWE-304

Missing Critical Step in Authentication

BaseDraft

Description

The product implements an authentication technique, but it skips a step that weakens the technique.

Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (44)

page 3 of 3
  • CVE-2023-3629MedDec 18, 2023
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

  • CVE-2022-39360MedOct 26, 2022
    risk 0.00cvss 6.5epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is…

  • CVE-2022-2821HigAug 15, 2022
    risk 0.00cvss 7.5epss 0.01

    Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

  • CVE-2021-41179MedOct 25, 2021
    risk 0.00cvss 6.5epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and 22.2.0, the Two-Factor Authentication wasn't enforced for pages marked as public. Any page marked as `@PublicPage` could thus be accessed with a valid user…