CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 35 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44394 | Med | 0.21 | 4.3 | 0.01 | Oct 16, 2023 | MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs. This issue has been addressed in commit `65c44883f` which has been… | ||
| CVE-2023-28336 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access. | ||
| CVE-2023-1402 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | The course participation report required additional checks to prevent roles being displayed which the user did not have access to view. | ||
| CVE-2022-33698 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log. | ||
| CVE-2021-20551 | Low | 0.21 | 3.3 | 0.00 | Jun 24, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 199149. | ||
| CVE-2022-27814 | Low | 0.21 | 3.3 | 0.00 | Apr 14, 2022 | SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option. | ||
| CVE-2022-27576 | Low | 0.21 | 3.3 | 0.00 | Apr 11, 2022 | Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission | ||
| CVE-2022-26850 | Med | 0.21 | 4.3 | 0.01 | Apr 6, 2022 | When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permissions. NiFi… | ||
| CVE-2021-4180 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2022 | An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would… | ||
| CVE-2022-0334 | Med | 0.21 | 4.3 | 0.01 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view… | ||
| CVE-2021-39628 | Low | 0.21 | 3.3 | 0.00 | Jan 14, 2022 | In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20620 | Med | 0.21 | 4.3 | 0.01 | Jan 12, 2022 | Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins. | ||
| CVE-2021-36319 | Low | 0.21 | 3.3 | 0.00 | Nov 20, 2021 | Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages. | ||
| CVE-2021-22468 | Low | 0.21 | 3.3 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage. | ||
| CVE-2021-25432 | Low | 0.21 | 3.3 | 0.00 | Jul 8, 2021 | Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data. | ||
| CVE-2021-31153 | Low | 0.21 | 3.3 | 0.00 | May 27, 2021 | please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option. | ||
| CVE-2021-26309 | Low | 0.21 | 3.3 | 0.00 | May 11, 2021 | Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions. | ||
| CVE-2020-11931 | Low | 0.21 | 3.3 | 0.00 | May 15, 2020 | An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy… | ||
| CVE-2019-8934 | Low | 0.21 | 3.3 | 0.01 | Mar 21, 2019 | hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest. | ||
| CVE-2023-4217 | Low | 0.20 | 3.1 | 0.00 | Nov 2, 2023 | A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and… |
- risk 0.21cvss 4.3epss 0.01
MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs. This issue has been addressed in commit `65c44883f` which has been…
- risk 0.21cvss 4.3epss 0.01
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
- risk 0.21cvss 4.3epss 0.01
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.
- risk 0.21cvss 3.3epss 0.00
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 199149.
- risk 0.21cvss 3.3epss 0.00
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option.
- risk 0.21cvss 3.3epss 0.00
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission
- risk 0.21cvss 4.3epss 0.01
When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permissions. NiFi…
- risk 0.21cvss 4.3epss 0.01
An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would…
- risk 0.21cvss 4.3epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view…
- risk 0.21cvss 3.3epss 0.00
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.21cvss 4.3epss 0.01
Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.
- risk 0.21cvss 3.3epss 0.00
Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages.
- risk 0.21cvss 3.3epss 0.00
A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage.
- risk 0.21cvss 3.3epss 0.00
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.
- risk 0.21cvss 3.3epss 0.00
please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.
- risk 0.21cvss 3.3epss 0.00
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
- risk 0.21cvss 3.3epss 0.00
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy…
- risk 0.21cvss 3.3epss 0.01
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
- risk 0.20cvss 3.1epss 0.00
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and…