VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 381 of 464
  • CVE-2022-2657MedSep 5, 2022
    risk 0.28cvss 4.3epss 0.00

    The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update…

  • CVE-2022-2376MedSep 5, 2022
    risk 0.28cvss 5.3epss 0.01

    The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

  • CVE-2022-2389MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to…

  • CVE-2022-2382MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.

  • CVE-2022-2276MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog

  • CVE-2022-2369MedAug 1, 2022
    risk 0.28cvss 4.3epss 0.01

    The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin

  • CVE-2022-36919MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-36918MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Buckminster Plugin 1.1.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36917MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers with Overall/Read permission to request a manual backup.

  • CVE-2022-36914MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36913MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36912MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

  • CVE-2022-36910MedJul 27, 2022
    risk 0.28cvss 5.4epss 0.00

    Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.

  • CVE-2022-36904MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

  • CVE-2022-36903MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Repository Connector Plugin 2.2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-36898MedJul 27, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

  • CVE-2022-31592MedJul 12, 2022
    risk 0.28cvss 4.3epss 0.01

    The application SAP Enterprise Extension Defense Forces & Public Security - versions 605, 606, 616,617,618, 802, 803, 804, 805, 806, does not perform necessary authorization checks for an authenticated user over the network, resulting in escalation of privileges leading to a…

  • CVE-2022-34818MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable jobs.

  • CVE-2022-34813MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions.

  • CVE-2022-34811MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page.