VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 39 of 88
  • CVE-2021-37304HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.04

    An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

  • CVE-2022-32778HigAug 22, 2022
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag,…

  • CVE-2022-32777HigAug 22, 2022
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag,…

  • CVE-2022-20234HigJul 13, 2022
    risk 0.49cvss 7.5epss 0.00

    In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName' and 'pkgTitle' from user.An unprivileged app can use a malicous mComponentName with a benign pkgTitle (e.g. Settings app) to make…

  • CVE-2022-32155HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.02

    In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your…

  • CVE-2022-1412HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenticated visitor to obtain potentially sensitive information like generated passwords.

  • CVE-2022-25151HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by…

  • CVE-2022-30990HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037

  • CVE-2022-26281HigApr 5, 2022
    risk 0.49cvss 7.5epss 0.01

    BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

  • CVE-2022-21819HigMar 11, 2022
    risk 0.49cvss 7.6epss 0.00

    NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through the PCI bus. Such an attack could…

  • CVE-2022-24327HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

  • CVE-2022-0247HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.00

    An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the…

  • CVE-2021-20874HigDec 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the…

  • CVE-2021-38154HigAug 29, 2021
    risk 0.49cvss 7.5epss 0.04

    Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail…

  • CVE-2021-36281HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can potentially exploit this vulnerability to escalate privileges.

  • CVE-2021-31902HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

  • CVE-2021-31918HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.

  • CVE-2020-27568HigApr 21, 2021
    risk 0.49cvss 7.5epss 0.02

    Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security.

  • CVE-2021-28374HigMar 15, 2021
    risk 0.49cvss 7.5epss 0.01

    The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password in some configurations. In general, it…

  • CVE-2020-25191HigDec 11, 2020
    risk 0.49cvss 7.5epss 0.01

    Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that could reboot the CompactRIO (Driver versions prior to 20.5) remotely.