VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,330)

page 116 of 117
  • CVE-2023-2260HigApr 24, 2023
    risk 0.00cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

  • CVE-2023-25160MedFeb 13, 2023
    risk 0.00cvss 4.1epss 0.00

    Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25,…

  • CVE-2023-22471LowJan 14, 2023
    risk 0.00cvss 3.5epss 0.01

    Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the…

  • CVE-2022-46179CriDec 28, 2022
    risk 0.00cvss 9.2epss 0.00

    LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is…

  • CVE-2022-4505HigDec 15, 2022
    risk 0.00cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.

  • CVE-2022-3019HigAug 29, 2022
    risk 0.00cvss 8.8epss 0.01

    The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).

  • CVE-2021-4142MedAug 24, 2022
    risk 0.00cvss 5.5epss 0.00

    The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

  • CVE-2022-2824HigAug 15, 2022
    risk 0.00cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-2730MedAug 9, 2022
    risk 0.00cvss 6.5epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

  • CVE-2022-31131MedJul 6, 2022
    risk 0.00cvss 5.4epss 0.01

    Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users.…

  • CVE-2022-29159MedMay 20, 2022
    risk 0.00cvss 5.0epss 0.01

    Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this…

  • CVE-2022-23061MedMay 1, 2022
    risk 0.00cvss 6.5epss 0.01

    In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.

  • CVE-2022-1461MedApr 25, 2022
    risk 0.00cvss 6.5epss 0.01

    Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2022-1459HigApr 25, 2022
    risk 0.00cvss 8.3epss 0.01

    Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2021-41111MedFeb 28, 2022
    risk 0.00cvss 6.4epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another…

  • CVE-2021-46249MedFeb 15, 2022
    risk 0.00cvss 6.5epss 0.01

    An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.

  • CVE-2021-3813MedFeb 9, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.

  • CVE-2022-21713MedFeb 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…

  • CVE-2021-3852HigJan 12, 2022
    risk 0.00cvss 7.5epss 0.01

    growi is vulnerable to Authorization Bypass Through User-Controlled Key

  • CVE-2021-43820HigDec 14, 2021
    risk 0.00cvss 7.4epss 0.01

    Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sync client or SeaDrive client, the server…