VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 424 of 464
  • CVE-2022-20620MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-20618MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-20616MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file.

  • CVE-2022-20614MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

  • CVE-2022-22108MedJan 5, 2022
    risk 0.21cvss 4.3epss 0.01

    In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view…

  • CVE-2022-22107MedJan 5, 2022
    risk 0.21cvss 4.3epss 0.01

    In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not…

  • CVE-2021-1034LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is installed, without querypermissions due to a missing permission check. This could lead to localinformation disclosure with no additional execution privileges needed.…

  • CVE-2021-0994LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2021-0982LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization name disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

  • CVE-2021-0978LowDec 15, 2021
    risk 0.21cvss 3.3epss 0.00

    In getSerialForPackage of DeviceIdentifiersPolicyService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2021-4089MedDec 10, 2021
    risk 0.21cvss 4.3epss 0.01

    snipe-it is vulnerable to Improper Access Control

  • CVE-2021-21674MedJun 30, 2021
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.

  • CVE-2021-21662MedJun 10, 2021
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2021-21654MedMay 11, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.

  • CVE-2021-21651MedMay 11, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain the list of configured profiles.

  • CVE-2021-21650MedMay 11, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoints and API models, allowing attackers with Item/Read permission to obtain information about artifacts uploaded to S3, if the optional Run/Artifacts permission…

  • CVE-2021-21647MedApr 21, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Item/Read permission to schedule builds of projects without having Item/Build permission.

  • CVE-2021-21645MedApr 21, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.

  • CVE-2021-21631MedMar 30, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.

  • CVE-2021-21625MedMar 18, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some circumstances.