CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (796)
page 17 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21605 | Med | 0.42 | 6.5 | 0.00 | Apr 12, 2024 | An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid link-local traffic is not blocked on… | ||
| CVE-2023-41120 | Med | 0.42 | 6.5 | 0.01 | Dec 12, 2023 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a… | ||
| CVE-2023-36013 | Med | 0.42 | 6.5 | 0.01 | Nov 20, 2023 | PowerShell Information Disclosure Vulnerability | ||
| CVE-2023-36043 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2023 | Open Management Infrastructure Information Disclosure Vulnerability | ||
| CVE-2023-36429 | Med | 0.42 | 6.5 | 0.02 | Oct 10, 2023 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | ||
| CVE-2023-39056 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39049 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39046 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39058 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39043 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39040 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39039 | Med | 0.42 | 6.5 | 0.01 | Sep 18, 2023 | An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-33368 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes. | ||
| CVE-2023-35151 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2023 | XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki… | ||
| CVE-2023-34467 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2023 | XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response… | ||
| CVE-2023-31103 | Hig | 0.42 | 7.5 | 0.01 | May 22, 2023 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's… | ||
| CVE-2023-31206 | Hig | 0.42 | 7.5 | 0.01 | May 22, 2023 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0… | ||
| CVE-2023-27564 | — | Hig | 0.42 | 7.5 | 0.01 | May 10, 2023 | The n8n package 0.218.0 for Node.js allows Information Disclosure. | |
| CVE-2023-2069 | Med | 0.42 | 6.4 | 0.01 | May 3, 2023 | An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD… | ||
| CVE-2023-0485 | Med | 0.42 | 6.5 | 0.01 | May 3, 2023 | An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates… |
- risk 0.42cvss 6.5epss 0.00
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid link-local traffic is not blocked on…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a…
- risk 0.42cvss 6.5epss 0.01
PowerShell Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Open Management Infrastructure Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.00
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.01
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.01
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
- risk 0.42cvss 7.5epss 0.01
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki…
- risk 0.42cvss 7.5epss 0.01
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response…
- risk 0.42cvss 7.5epss 0.01
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's…
- risk 0.42cvss 7.5epss 0.01
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0…
- risk 0.42cvss 7.5epss 0.01
The n8n package 0.218.0 for Node.js allows Information Disclosure.
- risk 0.42cvss 6.4epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD…
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates…