VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 384 of 464
  • CVE-2021-34629MedJul 30, 2021
    risk 0.28cvss 4.3epss 0.01

    The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and…

  • CVE-2021-20747MedJul 14, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

  • CVE-2021-22233MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

  • CVE-2021-20777MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

  • CVE-2021-29958MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.

  • CVE-2021-24355MedJun 14, 2021
    risk 0.28cvss 4.3epss 0.01

    In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to…

  • CVE-2021-21661MedJun 10, 2021
    risk 0.28cvss 4.3epss 0.02

    Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2021-21653MedMay 11, 2021
    risk 0.28cvss 4.3epss 0.01

    Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2021-20715MedApr 27, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Hot Pepper Gourmet App for Android ver.4.111.0 and earlier, and for iOS ver.4.111.0 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

  • CVE-2021-27605MedApr 13, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation of privileges. However, the attacker can only read some…

  • CVE-2021-30155MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.

  • CVE-2021-24164MedApr 5, 2021
    risk 0.28cvss 4.3epss 0.01

    In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already…

  • CVE-2021-21636MedMar 30, 2021
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2021-21626MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file…

  • CVE-2021-1143MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET requests. An attacker could…

  • CVE-2021-21467MedJan 12, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business Partner Generic Market Data (GMD), due to improper…

  • CVE-2019-11785MedDec 22, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future…

  • CVE-2020-26415MedDec 11, 2020
    risk 0.28cvss 4.3epss 0.01

    Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

  • CVE-2020-6316MedNov 10, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

  • CVE-2020-13794MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.01

    Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.