CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 17 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36429 | Med | 0.42 | 6.5 | 0.02 | Oct 10, 2023 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | ||
| CVE-2023-39056 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39049 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39046 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39058 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39043 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39040 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-39039 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2023 | An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | ||
| CVE-2023-33368 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes. | ||
| CVE-2023-35151 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2023 | XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki… | ||
| CVE-2023-34467 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2023 | XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response… | ||
| CVE-2023-31103 | Hig | 0.42 | 7.5 | 0.01 | May 22, 2023 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's… | ||
| CVE-2023-31206 | Hig | 0.42 | 7.5 | 0.01 | May 22, 2023 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0… | ||
| CVE-2023-27564 | — | Hig | 0.42 | 7.5 | 0.01 | May 10, 2023 | The n8n package 0.218.0 for Node.js allows Information Disclosure. | |
| CVE-2023-2069 | Med | 0.42 | 6.4 | 0.01 | May 3, 2023 | An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD… | ||
| CVE-2023-0485 | Med | 0.42 | 6.5 | 0.01 | May 3, 2023 | An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates… | ||
| CVE-2023-29208 | Hig | 0.42 | 7.5 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view… | ||
| CVE-2023-1777 | Med | 0.42 | 6.5 | 0.01 | Mar 31, 2023 | Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message. | ||
| CVE-2023-24906 | Med | 0.42 | 6.5 | 0.01 | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-24870 | Med | 0.42 | 6.5 | 0.01 | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
- risk 0.42cvss 6.5epss 0.02
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.00
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.00
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- risk 0.42cvss 6.5epss 0.01
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
- risk 0.42cvss 7.5epss 0.01
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki…
- risk 0.42cvss 7.5epss 0.01
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response…
- risk 0.42cvss 7.5epss 0.01
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's…
- risk 0.42cvss 7.5epss 0.01
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0…
- risk 0.42cvss 7.5epss 0.01
The n8n package 0.218.0 for Node.js allows Information Disclosure.
- risk 0.42cvss 6.4epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD…
- risk 0.42cvss 6.5epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates…
- risk 0.42cvss 7.5epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view…
- risk 0.42cvss 6.5epss 0.01
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
- risk 0.42cvss 6.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability