VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 382 of 464
  • CVE-2022-34798MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.

  • CVE-2022-34796MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-34785MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.

  • CVE-2022-0444MedJun 27, 2022
    risk 0.28cvss 4.3epss 0.00

    The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.

  • CVE-2022-34208MedJun 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

  • CVE-2022-34206MedJun 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.

  • CVE-2022-34204MedJun 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

  • CVE-2022-31095MedJun 21, 2022
    risk 0.28cvss 4.3epss 0.01

    discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup…

  • CVE-2022-24896MedJun 9, 2022
    risk 0.28cvss 4.3epss 0.01

    Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this…

  • CVE-2022-1203MedMay 30, 2022
    risk 0.28cvss 4.3epss 0.01

    The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify…

  • CVE-2021-42848MedMay 18, 2022
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.

  • CVE-2022-30957MedMay 17, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-1092MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.00

    The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog

  • CVE-2022-0634MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.00

    The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf…

  • CVE-2022-0363MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.00

    The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating…

  • CVE-2022-0287MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.01

    The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

  • CVE-2022-0390MedApr 1, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project non-members to retrieve issue details when it was linked to an item from the vulnerability dashboard.

  • CVE-2022-28151MedMar 29, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers with Item/Read permission to change the owners and item-specific permissions of a job.

  • CVE-2022-0833MedMar 28, 2022
    risk 0.28cvss 4.3epss 0.00

    The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible…

  • CVE-2022-27215MedMar 15, 2022
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.