VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,253)

page 458 of 463
  • CVE-2024-54679MedDec 5, 2024
    risk 0.00cvss 4.3epss 0.01

    CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

  • CVE-2024-53258MedNov 25, 2024
    risk 0.00cvss 5.3epss 0.00

    Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for…

  • CVE-2024-52554HigNov 13, 2024
    risk 0.00cvss 8.8epss 0.01

    Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a…

  • CVE-2024-52549MedNov 13, 2024
    risk 0.00cvss 4.3epss 0.00

    Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the…

  • CVE-2024-47768HigOct 4, 2024
    risk 0.00cvss 8.1epss 0.01

    Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct…

  • CVE-2024-9202MedSep 27, 2024
    risk 0.00cvss 5.3epss 0.00

    In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to…

  • CVE-2024-45393MedSep 10, 2024
    risk 0.00cvss 6.4epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each…

  • CVE-2024-45307HigSep 3, 2024
    risk 0.00cvss 8.8epss 0.00

    SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of…

  • CVE-2024-45058HigAug 28, 2024
    risk 0.00cvss 8.1epss 0.01

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to change their user type to…

  • CVE-2024-44069HigAug 19, 2024
    risk 0.00cvss 7.5epss 0.00

    Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value…

  • CVE-2024-37903HigJul 5, 2024
    risk 0.00cvss 8.2epss 0.01

    Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining…

  • CVE-2024-36113MedJul 3, 2024
    risk 0.00cvss 4.9epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users preventing them from logging in…

  • CVE-2024-37317MedJun 14, 2024
    risk 0.00cvss 4.6epss 0.00

    The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the…

  • CVE-2024-37314LowJun 14, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.

  • CVE-2024-4520HigJun 4, 2024
    risk 0.00cvss 7.5epss 0.01

    An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the…

  • CVE-2024-32466LowApr 18, 2024
    risk 0.00cvss 2.7epss 0.00

    Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user…

  • CVE-2024-2216HigMar 6, 2024
    risk 0.00cvss 8.8epss 0.01

    A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test…

  • CVE-2024-21630MedJan 25, 2024
    risk 0.00cvss 4.3epss 0.00

    Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be…

  • CVE-2023-50976CriDec 18, 2023
    risk 0.00cvss 9.8epss 0.01

    Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.

  • CVE-2023-43194MedNov 2, 2023
    risk 0.00cvss 5.3epss 0.01

    Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.