VYPR

CWE-732

Incorrect Permission Assignment for Critical Resource

ClassDraftLikelihood: High

Description

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642

CVEs mapped to this weakness (1,788)

page 89 of 90
  • CVE-2024-11584MedJun 26, 2025
    risk 0.00cvss 5.9epss 0.00

    cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could…

  • CVE-2025-49131MedJun 9, 2025
    risk 0.00cvss 6.3epss 0.00

    FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sandbox) is a specialized, isolated environment used by FastGPT to safely execute user-submitted or…

  • CVE-2024-41647CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.

  • CVE-2024-43199HigAug 7, 2024
    risk 0.00cvss 7.8epss 0.01

    Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

  • CVE-2024-41954MedJul 31, 2024
    risk 0.00cvss 5.3epss 0.00

    FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting these credentials, a malicious user could…

  • CVE-2024-27294HigFeb 29, 2024
    risk 0.00cvss 7.3epss 0.00

    dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive,…

  • CVE-2023-50446HigDec 10, 2023
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow any local unprivileged user to escalate privileges to SYSTEM.

  • CVE-2023-44387LowOct 5, 2023
    risk 0.00cvss 3.2epss 0.00

    Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissions of the linked file to the resulting…

  • CVE-2023-25817LowMar 27, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This issue has been addressed andit is…

  • CVE-2023-25150MedFeb 8, 2023
    risk 0.00cvss 5.8epss 0.01

    Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the…

  • CVE-2022-48257MedJan 13, 2023
    risk 0.00cvss 5.3epss 0.01

    In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.

  • CVE-2022-4630MedDec 21, 2022
    risk 0.00cvss 5.3epss 0.01

    Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.

  • CVE-2022-46338MedNov 30, 2022
    risk 0.00cvss 6.5epss 0.01

    g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.

  • CVE-2022-41926LowNov 25, 2022
    risk 0.00cvss 3.3epss 0.00

    Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malicious apps to monitor communication. It is recommended that the Nextcloud Talk Android is upgraded to…

  • CVE-2022-39207MedSep 13, 2022
    risk 0.00cvss 5.4epss 0.01

    Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. These artifact files are served by the…

  • CVE-2022-24886LowApr 27, 2022
    risk 0.00cvss 2.2epss 0.00

    Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Contacts permission itself.…

  • CVE-2022-29527HigApr 20, 2022
    risk 0.00cvss 7.0epss 0.00

    Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.

  • CVE-2022-1316HigApr 11, 2022
    risk 0.00cvss 8.8epss 0.00

    Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation

  • CVE-2022-25010CriMar 1, 2022
    risk 0.00cvss 9.1epss 0.01

    The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.

  • CVE-2022-0532MedFeb 9, 2022
    risk 0.00cvss 4.2epss 0.01

    An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.