VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,752)

page 81 of 88
  • CVE-2022-20616MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file.

  • CVE-2022-20614MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

  • CVE-2016-11080MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.

  • CVE-2016-11065MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.

  • CVE-2017-18878MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.

  • CVE-2017-18872MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.

  • CVE-2019-19087MedJan 3, 2020
    risk 0.21cvss 4.3epss 0.01

    Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).

  • CVE-2019-19086MedJan 3, 2020
    risk 0.21cvss 4.3epss 0.01

    Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).

  • CVE-2012-6655LowNov 27, 2019
    risk 0.21cvss 3.3epss 0.00

    An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

  • CVE-2019-13679LowNov 25, 2019
    risk 0.21cvss 3.3epss 0.01

    Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.

  • CVE-2019-15340LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006)…

  • CVE-2019-15339LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the…

  • CVE-2019-15338LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app…

  • CVE-2019-15337LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device…

  • CVE-2019-15336LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app…

  • CVE-2019-15335LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device…

  • CVE-2019-15334LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app…

  • CVE-2019-15333LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the…

  • CVE-2019-5642LowNov 6, 2019
    risk 0.21cvss 3.3epss 0.00

    Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is…

  • CVE-2016-4983LowNov 5, 2019
    risk 0.21cvss 3.3epss 0.00

    A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.