VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 56 of 88
  • CVE-2019-13665MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a crafted HTML page.

  • CVE-2019-14824MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

  • CVE-2015-9456MedOct 7, 2019
    risk 0.42cvss 6.5epss 0.01

    The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter.

  • CVE-2019-16187HigSep 9, 2019
    risk 0.42cvss 7.5epss 0.01

    Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.

  • CVE-2018-12357MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.

  • CVE-2018-14862MedJul 3, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.

  • CVE-2018-14861MedJul 3, 2019
    risk 0.42cvss 6.5epss 0.01

    Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users.

  • CVE-2019-13012HigJun 28, 2019
    risk 0.42cvss 7.5epss 0.03

    The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION,…

  • CVE-2019-8283MedJun 7, 2019
    risk 0.42cvss 6.5epss 0.01

    Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.

  • CVE-2019-10115MedMay 16, 2019
    risk 0.42cvss 6.5epss 0.01

    An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The GitLab Releases feature could allow guest users access to private information like release details and code…

  • CVE-2019-10110MedMay 15, 2019
    risk 0.42cvss 6.5epss 0.01

    An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. The "move issue" feature may allow a user to create projects under any namespace on any GitLab instance on which…

  • CVE-2018-19589MedApr 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM product package allows an SO authenticated to a slot to retrieve attributes of keys marked as private keys in external key storage, and also delete keys marked…

  • CVE-2018-12546MedMar 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this…

  • CVE-2018-18495MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.02

    WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be…

  • CVE-2018-12396MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR <…

  • CVE-2018-18812MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.01

    The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability that might theoretically fail to restrict users with read-only access from modifying files stored in the Spotfire…

  • CVE-2018-18352MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass same origin policy for audio content via a crafted HTML page.

  • CVE-2018-18349MedDec 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.

  • CVE-2018-13355MedNov 27, 2018
    risk 0.42cvss 6.5epss 0.01

    Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization.

  • CVE-2018-14934MedNov 15, 2018
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone.