VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 67 of 88
  • CVE-2021-20416MedJul 7, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force…

  • CVE-2020-1701MedMay 27, 2021
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

  • CVE-2021-20996MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.

  • CVE-2021-31907MedMay 11, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.

  • CVE-2021-29247MedMay 5, 2021
    risk 0.35cvss 5.3epss 0.01

    BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.

  • CVE-2021-22850MedJan 19, 2021
    risk 0.35cvss 5.3epss 0.01

    HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.

  • CVE-2020-4625MedNov 30, 2020
    risk 0.35cvss 5.3epss 0.01

    IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.

  • CVE-2020-28053MedNov 23, 2020
    risk 0.35cvss 6.5epss 0.01

    HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.

  • CVE-2020-6267MedJul 14, 2020
    risk 0.35cvss 5.4epss 0.01

    Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.

  • CVE-2018-21265MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

  • CVE-2020-11911MedJun 17, 2020
    risk 0.35cvss 5.3epss 0.03

    The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.

  • CVE-2019-20693MedApr 16, 2020
    risk 0.35cvss 5.4epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

  • CVE-2020-4289MedApr 8, 2020
    risk 0.35cvss 5.3epss 0.02

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information…

  • CVE-2020-7050MedFeb 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal…

  • CVE-2011-4912MedFeb 4, 2020
    risk 0.35cvss 5.3epss 0.01

    Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.

  • CVE-2019-18456MedNov 26, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).

  • CVE-2019-18452MedNov 26, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

  • CVE-2019-18459MedNov 26, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

  • CVE-2019-6465MedOct 9, 2019
    risk 0.35cvss 5.3epss 0.04

    Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition.…

  • CVE-2019-12245MedSep 25, 2019
    risk 0.35cvss 5.3epss 0.01

    SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension.