VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 54 of 88
  • CVE-2023-35147MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.

  • CVE-2023-31454HigMay 22, 2023
    risk 0.42cvss 7.5epss 0.01

    Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.  The attacker can bind any cluster, even if he is not the cluster owner. Users are advised to upgrade to…

  • CVE-2023-31453HigMay 22, 2023
    risk 0.42cvss 7.5epss 0.01

    Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the deleted…

  • CVE-2023-32990MedMay 16, 2023
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.

  • CVE-2022-41771MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2023-30512MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.01

    CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.

  • CVE-2023-27096MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController function of the Tenant Management module.

  • CVE-2023-27095MedMar 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.

  • CVE-2023-23610MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to…

  • CVE-2022-42949HigDec 21, 2022
    risk 0.42cvss 7.5epss 0.01

    Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.

  • CVE-2022-23143MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.01

    ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.

  • CVE-2022-2188MedNov 7, 2022
    risk 0.42cvss 6.5epss 0.00

    Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.

  • CVE-2022-26240MedOct 6, 2022
    risk 0.42cvss 6.5epss 0.01

    The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

  • CVE-2022-22411MedAug 10, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.

  • CVE-2022-1655MedJul 22, 2022
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of…

  • CVE-2022-34012MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.

  • CVE-2022-1596MedJun 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.

  • CVE-2021-40649MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.01

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

  • CVE-2022-1348MedMay 25, 2022
    risk 0.42cvss 6.5epss 0.02

    A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable…

  • CVE-2021-23055MedApr 21, 2022
    risk 0.42cvss 6.5epss 0.01

    On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.