VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,392)

page 256 of 270
  • CVE-2022-45389Nov 15, 2022
    risk 0.00cvss epss 0.02

    A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.

  • CVE-2022-45390Nov 15, 2022
    risk 0.00cvss epss 0.01

    A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-45399Nov 15, 2022
    risk 0.00cvss epss 0.00

    A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.

  • CVE-2022-45394Nov 15, 2022
    risk 0.00cvss epss 0.00

    A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.

  • CVE-2022-40308Nov 15, 2022
    risk 0.00cvss epss 0.01

    If anonymous read enabled, it's possible to read the database file directly without logging in.

  • CVE-2022-40309Nov 15, 2022
    risk 0.00cvss epss 0.01

    Users with write permissions to a repository can delete arbitrary directories.

  • CVE-2022-45385Nov 15, 2022
    risk 0.00cvss epss 0.02

    A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

  • CVE-2022-39340Oct 25, 2022
    risk 0.00cvss epss 0.00

    OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA…

  • CVE-2022-43431Oct 19, 2022
    risk 0.00cvss epss 0.01

    Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-43413Oct 19, 2022
    risk 0.00cvss epss 0.01

    Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-43417Oct 19, 2022
    risk 0.00cvss epss 0.01

    Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing…

  • CVE-2022-43421Oct 19, 2022
    risk 0.00cvss epss 0.03

    A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects whose configured repository matches the attacker-specified value.

  • CVE-2022-43427Oct 19, 2022
    risk 0.00cvss epss 0.01

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-39222Oct 6, 2022
    risk 0.00cvss epss 0.01

    Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are running a version prior to…

  • CVE-2022-40316Sep 30, 2022
    risk 0.00cvss epss 0.00

    The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

  • CVE-2021-41803Sep 23, 2022
    risk 0.00cvss epss 0.00

    HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

  • CVE-2022-38512Sep 22, 2022
    risk 0.00cvss epss 0.00

    The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via…

  • CVE-2022-39975Sep 21, 2022
    risk 0.00cvss epss 0.00

    The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via…

  • CVE-2022-41254Sep 21, 2022
    risk 0.00cvss epss 0.01

    Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-41252Sep 21, 2022
    risk 0.00cvss epss 0.00

    Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.