CWE-732
Incorrect Permission Assignment for Critical Resource
Description
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642
CVEs mapped to this weakness (1,752)
page 76 of 88| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26932 | Med | 0.28 | 4.3 | 0.01 | Oct 10, 2020 | debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group) | ||
| CVE-2020-15697 | Med | 0.28 | 4.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users. | ||
| CVE-2017-18916 | Med | 0.28 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction. | ||
| CVE-2016-11062 | Med | 0.28 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed. | ||
| CVE-2017-18910 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links. | ||
| CVE-2017-18896 | Med | 0.28 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint. | ||
| CVE-2018-21256 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command. | ||
| CVE-2018-21252 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups. | ||
| CVE-2018-21261 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges. | ||
| CVE-2018-21255 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel. | ||
| CVE-2018-21254 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command. | ||
| CVE-2018-21253 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user. | ||
| CVE-2017-18870 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case. | ||
| CVE-2020-12797 | Med | 0.28 | 5.3 | 0.02 | Jun 11, 2020 | HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4. | ||
| CVE-2019-4603 | Med | 0.28 | 4.3 | 0.01 | Apr 8, 2020 | IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user. IBM X-Force ID: 168295. | ||
| CVE-2019-19263 | Med | 0.28 | 4.3 | 0.01 | Jan 3, 2020 | GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions. | ||
| CVE-2019-19262 | Med | 0.28 | 4.3 | 0.01 | Jan 3, 2020 | GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions. | ||
| CVE-2019-18453 | Med | 0.28 | 4.3 | 0.01 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions. | ||
| CVE-2019-18450 | Med | 0.28 | 4.3 | 0.01 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions. | ||
| CVE-2019-18449 | Med | 0.28 | 4.3 | 0.01 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2). |
- risk 0.28cvss 4.3epss 0.01
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
- risk 0.28cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.
- risk 0.28cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.
- risk 0.28cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
- risk 0.28cvss 5.3epss 0.02
HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.
- risk 0.28cvss 4.3epss 0.01
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user. IBM X-Force ID: 168295.
- risk 0.28cvss 4.3epss 0.01
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
- risk 0.28cvss 4.3epss 0.01
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).