VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,392)

page 262 of 270
  • CVE-2022-20614Jan 12, 2022
    risk 0.00cvss epss 0.00

    A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

  • CVE-2022-0179Jan 12, 2022
    risk 0.00cvss epss 0.00

    snipe-it is vulnerable to Missing Authorization

  • CVE-2022-22111Jan 5, 2022
    risk 0.00cvss epss 0.00

    In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the…

  • CVE-2022-22108Jan 5, 2022
    risk 0.00cvss epss 0.00

    In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view…

  • CVE-2022-22107Jan 5, 2022
    risk 0.00cvss epss 0.00

    In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not…

  • CVE-2021-4089Dec 10, 2021
    risk 0.00cvss epss 0.00

    snipe-it is vulnerable to Improper Access Control

  • CVE-2021-43781Dec 6, 2021
    risk 0.00cvss epss 0.00

    Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable…

  • CVE-2021-39236Nov 19, 2021
    risk 0.00cvss epss 0.01

    In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

  • CVE-2021-39232Nov 19, 2021
    risk 0.00cvss epss 0.00

    In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

  • CVE-2021-39231Nov 19, 2021
    risk 0.00cvss epss 0.01

    In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

  • CVE-2021-21695Nov 4, 2021
    risk 0.00cvss epss 0.01

    FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-21694Nov 4, 2021
    risk 0.00cvss epss 0.00

    FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-21689Nov 4, 2021
    risk 0.00cvss epss 0.01

    FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-21688Nov 4, 2021
    risk 0.00cvss epss 0.00

    The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operations, allowing users to have unrestricted read access using certain operations (creating archives, FilePath#copyRecursiveTo).

  • CVE-2021-21687Nov 4, 2021
    risk 0.00cvss epss 0.00

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.

  • CVE-2021-21685Nov 4, 2021
    risk 0.00cvss epss 0.00

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs.

  • CVE-2021-41238Nov 2, 2021
    risk 0.00cvss epss 0.00

    Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process required. Dashboard UI in Hangfire.Core uses authorization filters to protect it from showing sensitive data to unauthorized users.…

  • CVE-2021-39184Oct 12, 2021
    risk 0.00cvss epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The…

  • CVE-2021-22147Sep 15, 2021
    risk 0.00cvss epss 0.00

    Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

  • CVE-2021-38698Sep 7, 2021
    risk 0.00cvss epss 0.00

    HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.