CWE-639
Authorization Bypass Through User-Controlled Key
Description
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Hierarchy (View 1000)
CVEs mapped to this weakness (2,330)
page 116 of 117| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2260 | Hig | 0.00 | 8.8 | 0.01 | Apr 24, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. | ||
| CVE-2023-25160 | Med | 0.00 | 4.1 | 0.00 | Feb 13, 2023 | Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25,… | ||
| CVE-2023-22471 | Low | 0.00 | 3.5 | 0.01 | Jan 14, 2023 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the… | ||
| CVE-2022-46179 | Cri | 0.00 | 9.2 | 0.00 | Dec 28, 2022 | LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is… | ||
| CVE-2022-4505 | Hig | 0.00 | 8.8 | 0.01 | Dec 15, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2. | ||
| CVE-2022-3019 | Hig | 0.00 | 8.8 | 0.01 | Aug 29, 2022 | The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one). | ||
| CVE-2021-4142 | Med | 0.00 | 5.5 | 0.00 | Aug 24, 2022 | The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin. | ||
| CVE-2022-2824 | Hig | 0.00 | 8.8 | 0.01 | Aug 15, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2730 | Med | 0.00 | 6.5 | 0.01 | Aug 9, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-31131 | Med | 0.00 | 5.4 | 0.01 | Jul 6, 2022 | Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users.… | ||
| CVE-2022-29159 | Med | 0.00 | 5.0 | 0.01 | May 20, 2022 | Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this… | ||
| CVE-2022-23061 | Med | 0.00 | 6.5 | 0.01 | May 1, 2022 | In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability. | ||
| CVE-2022-1461 | Med | 0.00 | 6.5 | 0.01 | Apr 25, 2022 | Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1459 | Hig | 0.00 | 8.3 | 0.01 | Apr 25, 2022 | Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2021-41111 | Med | 0.00 | 6.4 | 0.01 | Feb 28, 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another… | ||
| CVE-2021-46249 | Med | 0.00 | 6.5 | 0.01 | Feb 15, 2022 | An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps. | ||
| CVE-2021-3813 | Med | 0.00 | 6.5 | 0.01 | Feb 9, 2022 | Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. | ||
| CVE-2022-21713 | Med | 0.00 | 4.3 | 0.01 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the… | ||
| CVE-2021-3852 | Hig | 0.00 | 7.5 | 0.01 | Jan 12, 2022 | growi is vulnerable to Authorization Bypass Through User-Controlled Key | ||
| CVE-2021-43820 | Hig | 0.00 | 7.4 | 0.01 | Dec 14, 2021 | Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sync client or SeaDrive client, the server… |
- risk 0.00cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
- risk 0.00cvss 4.1epss 0.00
Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25,…
- risk 0.00cvss 3.5epss 0.01
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the…
- risk 0.00cvss 9.2epss 0.00
LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is…
- risk 0.00cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
- risk 0.00cvss 8.8epss 0.01
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).
- risk 0.00cvss 5.5epss 0.00
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
- risk 0.00cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 6.5epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 5.4epss 0.01
Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users.…
- risk 0.00cvss 5.0epss 0.01
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this…
- risk 0.00cvss 6.5epss 0.01
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
- risk 0.00cvss 6.5epss 0.01
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 8.3epss 0.01
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 6.4epss 0.01
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another…
- risk 0.00cvss 6.5epss 0.01
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.
- risk 0.00cvss 6.5epss 0.01
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
- risk 0.00cvss 4.3epss 0.01
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…
- risk 0.00cvss 7.5epss 0.01
growi is vulnerable to Authorization Bypass Through User-Controlled Key
- risk 0.00cvss 7.4epss 0.01
Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sync client or SeaDrive client, the server…