CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 380 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4103 | Med | 0.28 | 4.3 | 0.00 | Jan 9, 2023 | The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any… | ||
| CVE-2022-3923 | Med | 0.28 | 4.3 | 0.00 | Jan 9, 2023 | The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs. | ||
| CVE-2022-4124 | Med | 0.28 | 4.3 | 0.00 | Dec 19, 2022 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them | ||
| CVE-2022-43482 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2022 | Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. | ||
| CVE-2022-41692 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2022 | Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress. | ||
| CVE-2022-3920 | Med | 0.28 | 5.3 | 0.01 | Nov 16, 2022 | HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0. | ||
| CVE-2022-45399 | Med | 0.28 | 4.3 | 0.01 | Nov 15, 2022 | A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics. | ||
| CVE-2022-45394 | Med | 0.28 | 4.3 | 0.01 | Nov 15, 2022 | A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs. | ||
| CVE-2022-45390 | Med | 0.28 | 4.3 | 0.01 | Nov 15, 2022 | A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | ||
| CVE-2022-2450 | Med | 0.28 | 4.3 | 0.00 | Nov 14, 2022 | The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them. | ||
| CVE-2022-3451 | Med | 0.28 | 4.3 | 0.00 | Nov 7, 2022 | The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options | ||
| CVE-2022-39340 | Med | 0.28 | 5.3 | 0.01 | Oct 25, 2022 | OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA… | ||
| CVE-2022-39233 | Med | 0.28 | 4.3 | 0.01 | Oct 19, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration.… | ||
| CVE-2022-40316 | Med | 0.28 | 4.3 | 0.01 | Sep 30, 2022 | The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | ||
| CVE-2022-2405 | Med | 0.28 | 4.3 | 0.00 | Sep 26, 2022 | The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup | ||
| CVE-2022-35249 | Med | 0.28 | 4.3 | 0.01 | Sep 23, 2022 | A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room. | ||
| CVE-2022-35247 | Med | 0.28 | 4.3 | 0.01 | Sep 23, 2022 | A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients. | ||
| CVE-2022-39975 | Med | 0.28 | 4.3 | 0.00 | Sep 22, 2022 | The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via… | ||
| CVE-2022-41252 | Med | 0.28 | 4.3 | 0.01 | Sep 21, 2022 | Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins. | ||
| CVE-2022-41251 | Med | 0.28 | 4.3 | 0.01 | Sep 21, 2022 | A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |
- risk 0.28cvss 4.3epss 0.00
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any…
- risk 0.28cvss 4.3epss 0.00
The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.
- risk 0.28cvss 4.3epss 0.00
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them
- risk 0.28cvss 4.3epss 0.00
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.
- risk 0.28cvss 4.3epss 0.00
Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.
- risk 0.28cvss 5.3epss 0.01
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
- risk 0.28cvss 4.3epss 0.01
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.
- risk 0.28cvss 4.3epss 0.01
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.
- risk 0.28cvss 4.3epss 0.01
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
- risk 0.28cvss 4.3epss 0.00
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.
- risk 0.28cvss 4.3epss 0.00
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options
- risk 0.28cvss 5.3epss 0.01
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA…
- risk 0.28cvss 4.3epss 0.01
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration.…
- risk 0.28cvss 4.3epss 0.01
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
- risk 0.28cvss 4.3epss 0.00
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
- risk 0.28cvss 4.3epss 0.01
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
- risk 0.28cvss 4.3epss 0.01
A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients.
- risk 0.28cvss 4.3epss 0.00
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via…
- risk 0.28cvss 4.3epss 0.01
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
- risk 0.28cvss 4.3epss 0.01
A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.