VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 76 of 88
  • CVE-2020-26932MedOct 10, 2020
    risk 0.28cvss 4.3epss 0.01

    debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

  • CVE-2020-15697MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.

  • CVE-2017-18916MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.

  • CVE-2016-11062MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.

  • CVE-2017-18910MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.

  • CVE-2017-18896MedJun 19, 2020
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.

  • CVE-2018-21256MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.

  • CVE-2018-21252MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.

  • CVE-2018-21261MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.

  • CVE-2018-21255MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.

  • CVE-2018-21254MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.

  • CVE-2018-21253MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.

  • CVE-2017-18870MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.

  • CVE-2020-12797MedJun 11, 2020
    risk 0.28cvss 5.3epss 0.02

    HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

  • CVE-2019-4603MedApr 8, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user. IBM X-Force ID: 168295.

  • CVE-2019-19263MedJan 3, 2020
    risk 0.28cvss 4.3epss 0.01

    GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

  • CVE-2019-19262MedJan 3, 2020
    risk 0.28cvss 4.3epss 0.01

    GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.

  • CVE-2019-18453MedNov 26, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.

  • CVE-2019-18450MedNov 26, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.

  • CVE-2019-18449MedNov 26, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).