VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 75 of 88
  • CVE-2023-32979MedMay 16, 2023
    risk 0.28cvss 4.3epss 0.01

    Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file…

  • CVE-2023-28522MedMay 12, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.

  • CVE-2023-1939MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.00

    No access control for the OTP key   on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.

  • CVE-2023-0944MedApr 5, 2023
    risk 0.28cvss 4.3epss 0.00

    Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not correctly validate user permissions with…

  • CVE-2023-0225MedApr 3, 2023
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.

  • CVE-2022-45307MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.00

    Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.

  • CVE-2022-45306MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.00

    Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.

  • CVE-2022-45305MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.00

    Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.

  • CVE-2022-45304MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.00

    Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder.

  • CVE-2022-45301MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.00

    Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.

  • CVE-2022-32169MedSep 28, 2022
    risk 0.28cvss 4.3epss 0.01

    The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.

  • CVE-2022-40817MedSep 27, 2022
    risk 0.28cvss 4.3epss 0.00

    Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in…

  • CVE-2022-35250MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions.

  • CVE-2020-1754MedAug 5, 2022
    risk 0.28cvss 4.3epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

  • CVE-2022-36800MedAug 3, 2022
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version…

  • CVE-2021-39868MedOct 4, 2021
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

  • CVE-2021-35202MedSep 30, 2021
    risk 0.28cvss 4.3epss 0.01

    NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.

  • CVE-2021-36129MedJul 2, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silently delete various…

  • CVE-2021-31929MedJun 10, 2021
    risk 0.28cvss 4.3epss 0.01

    Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.

  • CVE-2021-32056MedMay 10, 2021
    risk 0.28cvss 4.3epss 0.02

    Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.