VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 379 of 464
  • CVE-2023-30522MedApr 12, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to trigger builds of jobs specified in a 'jobname' request parameter.

  • CVE-2023-30518MedApr 12, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-1903MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.00

    SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data.

  • CVE-2023-28675MedApr 2, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a previously configured Octoperf server using attacker-specified credentials.

  • CVE-2023-28673MedApr 2, 2023
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-4148MedMar 20, 2023
    risk 0.28cvss 4.3epss 0.00

    The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

  • CVE-2022-4932MedMar 7, 2023
    risk 0.28cvss 4.3epss 0.01

    The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated…

  • CVE-2023-1023MedFeb 28, 2023
    risk 0.28cvss 5.4epss 0.01

    The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the saveSitemapSettings function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level…

  • CVE-2023-1022MedFeb 28, 2023
    risk 0.28cvss 5.4epss 0.01

    The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on the wpmsGGSaveInformation function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to…

  • CVE-2023-27263MedFeb 27, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

  • CVE-2022-4385MedFeb 21, 2023
    risk 0.28cvss 4.3epss 0.00

    The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order

  • CVE-2023-23850MedFeb 15, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-23848MedFeb 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…

  • CVE-2022-4872MedJan 30, 2023
    risk 0.28cvss 4.3epss 0.00

    The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'

  • CVE-2023-24451MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Cisco Spark Notifier Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-24436MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-24431MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2023-23611MedJan 26, 2023
    risk 0.28cvss 5.4epss 0.00

    LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and above, prior to 7.2.2, are vulnerable to Missing Authorization. Any LTI tool that is integrated with on the Open edX platform can…

  • CVE-2023-0447MedJan 23, 2023
    risk 0.28cvss 4.3epss 0.01

    The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_all_cache function in versions up to, and including, 3.0.12.1. This makes it possible for authenticated attackers, with subscriber-level permissions…

  • CVE-2023-0293MedJan 13, 2023
    risk 0.28cvss 4.3epss 0.01

    The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with subscriber-level…