VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 17 of 40
  • CVE-2023-36429MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

  • CVE-2023-39056MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39049MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39046MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39058MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39043MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39040MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-39039MedSep 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

  • CVE-2023-33368MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.

  • CVE-2023-35151HigJun 23, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki…

  • CVE-2023-34467HigJun 23, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response…

  • CVE-2023-31103HigMay 22, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's…

  • CVE-2023-31206HigMay 22, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0…

  • CVE-2023-27564HigMay 10, 2023
    risk 0.42cvss 7.5epss 0.01

    The n8n package 0.218.0 for Node.js allows Information Disclosure.

  • CVE-2023-2069MedMay 3, 2023
    risk 0.42cvss 6.4epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD…

  • CVE-2023-0485MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates…

  • CVE-2023-29208HigApr 15, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view…

  • CVE-2023-1777MedMar 31, 2023
    risk 0.42cvss 6.5epss 0.01

    Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

  • CVE-2023-24906MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-24870MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability