CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (5,392)
page 262 of 270| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20614 | 0.00 | — | 0.00 | Jan 12, 2022 | A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname. | |||
| CVE-2022-0179 | 0.00 | — | 0.00 | Jan 12, 2022 | snipe-it is vulnerable to Missing Authorization | |||
| CVE-2022-22111 | 0.00 | — | 0.00 | Jan 5, 2022 | In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the… | |||
| CVE-2022-22108 | 0.00 | — | 0.00 | Jan 5, 2022 | In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view… | |||
| CVE-2022-22107 | 0.00 | — | 0.00 | Jan 5, 2022 | In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not… | |||
| CVE-2021-4089 | 0.00 | — | 0.00 | Dec 10, 2021 | snipe-it is vulnerable to Improper Access Control | |||
| CVE-2021-43781 | 0.00 | — | 0.00 | Dec 6, 2021 | Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable… | |||
| CVE-2021-39236 | — | 0.00 | — | 0.01 | Nov 19, 2021 | In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. | ||
| CVE-2021-39232 | — | 0.00 | — | 0.00 | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins. | ||
| CVE-2021-39231 | — | 0.00 | — | 0.01 | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration. | ||
| CVE-2021-21695 | 0.00 | — | 0.01 | Nov 4, 2021 | FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. | |||
| CVE-2021-21694 | 0.00 | — | 0.00 | Nov 4, 2021 | FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. | |||
| CVE-2021-21689 | 0.00 | — | 0.01 | Nov 4, 2021 | FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. | |||
| CVE-2021-21688 | 0.00 | — | 0.00 | Nov 4, 2021 | The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operations, allowing users to have unrestricted read access using certain operations (creating archives, FilePath#copyRecursiveTo). | |||
| CVE-2021-21687 | 0.00 | — | 0.00 | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar. | |||
| CVE-2021-21685 | 0.00 | — | 0.00 | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs. | |||
| CVE-2021-41238 | 0.00 | — | 0.00 | Nov 2, 2021 | Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process required. Dashboard UI in Hangfire.Core uses authorization filters to protect it from showing sensitive data to unauthorized users.… | |||
| CVE-2021-39184 | 0.00 | — | 0.00 | Oct 12, 2021 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The… | |||
| CVE-2021-22147 | 0.00 | — | 0.00 | Sep 15, 2021 | Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view. | |||
| CVE-2021-38698 | — | 0.00 | — | 0.00 | Sep 7, 2021 | HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2. |
- CVE-2022-20614Jan 12, 2022risk 0.00cvss —epss 0.00
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
- CVE-2022-0179Jan 12, 2022risk 0.00cvss —epss 0.00
snipe-it is vulnerable to Missing Authorization
- CVE-2022-22111Jan 5, 2022risk 0.00cvss —epss 0.00
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the…
- CVE-2022-22108Jan 5, 2022risk 0.00cvss —epss 0.00
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view…
- CVE-2022-22107Jan 5, 2022risk 0.00cvss —epss 0.00
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not…
- CVE-2021-4089Dec 10, 2021risk 0.00cvss —epss 0.00
snipe-it is vulnerable to Improper Access Control
- CVE-2021-43781Dec 6, 2021risk 0.00cvss —epss 0.00
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable…
- CVE-2021-39236Nov 19, 2021risk 0.00cvss —epss 0.01
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
- CVE-2021-39232Nov 19, 2021risk 0.00cvss —epss 0.00
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
- CVE-2021-39231Nov 19, 2021risk 0.00cvss —epss 0.01
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.
- CVE-2021-21695Nov 4, 2021risk 0.00cvss —epss 0.01
FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
- CVE-2021-21694Nov 4, 2021risk 0.00cvss —epss 0.00
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
- CVE-2021-21689Nov 4, 2021risk 0.00cvss —epss 0.01
FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
- CVE-2021-21688Nov 4, 2021risk 0.00cvss —epss 0.00
The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operations, allowing users to have unrestricted read access using certain operations (creating archives, FilePath#copyRecursiveTo).
- CVE-2021-21687Nov 4, 2021risk 0.00cvss —epss 0.00
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.
- CVE-2021-21685Nov 4, 2021risk 0.00cvss —epss 0.00
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs.
- CVE-2021-41238Nov 2, 2021risk 0.00cvss —epss 0.00
Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process required. Dashboard UI in Hangfire.Core uses authorization filters to protect it from showing sensitive data to unauthorized users.…
- CVE-2021-39184Oct 12, 2021risk 0.00cvss —epss 0.00
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The…
- CVE-2021-22147Sep 15, 2021risk 0.00cvss —epss 0.00
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
- CVE-2021-38698Sep 7, 2021risk 0.00cvss —epss 0.00
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.