CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,259)
page 459 of 463| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-4520 | Hig | 0.00 | 7.5 | 0.01 | Jun 4, 2024 | An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the… | ||
| CVE-2024-32466 | Low | 0.00 | 2.7 | 0.00 | Apr 18, 2024 | Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user… | ||
| CVE-2024-2216 | Hig | 0.00 | 8.8 | 0.01 | Mar 6, 2024 | A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test… | ||
| CVE-2024-21630 | Med | 0.00 | 4.3 | 0.00 | Jan 25, 2024 | Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be… | ||
| CVE-2023-50976 | Cri | 0.00 | 9.8 | 0.01 | Dec 18, 2023 | Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API. | ||
| CVE-2023-43194 | Med | 0.00 | 5.3 | 0.01 | Nov 2, 2023 | Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter. | ||
| CVE-2023-5862 | Low | 0.00 | 3.3 | 0.00 | Oct 31, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to Build95. | ||
| CVE-2023-5321 | Med | 0.00 | 5.5 | 0.00 | Sep 30, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to build94. | ||
| CVE-2023-4104 | Med | 0.00 | 5.5 | 0.00 | Sep 11, 2023 | An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN… | ||
| CVE-2023-41908 | Med | 0.00 | 5.3 | 0.00 | Sep 5, 2023 | Cerebrate before 1.15 lacks the Secure attribute for the session cookie. | ||
| CVE-2023-4434 | Med | 0.00 | 6.1 | 0.00 | Aug 20, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to build88. | ||
| CVE-2023-40216 | Med | 0.00 | 5.5 | 0.00 | Aug 10, 2023 | OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences. | ||
| CVE-2023-38494 | Med | 0.00 | 5.9 | 0.00 | Aug 4, 2023 | MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue. | ||
| CVE-2023-38510 | Hig | 0.00 | 8.1 | 0.01 | Jul 27, 2023 | Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request is made using an API key, the backend fails to verify the permission scopes associated with the key, effectively bypassing permission checks entirely for some… | ||
| CVE-2023-3230 | Hig | 0.00 | 7.5 | 0.00 | Jun 14, 2023 | Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0. | ||
| CVE-2023-33970 | Med | 0.00 | 5.4 | 0.01 | Jun 5, 2023 | Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a `missing access control` was found, which allows a User with the lowest privileges to leak all the tasks and projects titles within the software, even if they… | ||
| CVE-2023-33968 | Med | 0.00 | 5.4 | 0.00 | Jun 5, 2023 | Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to a missing access control vulnerability that allows a user with low privileges to create or transfer tasks to any project within the software, even… | ||
| CVE-2023-2945 | Med | 0.00 | 5.4 | 0.00 | May 27, 2023 | Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1. | ||
| CVE-2023-28623 | Med | 0.00 | 6.5 | 0.01 | May 19, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabled in… | ||
| CVE-2023-32677 | Low | 0.00 | 3.1 | 0.01 | May 19, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server 6.1 and below, the UI which allows… |
- risk 0.00cvss 7.5epss 0.01
An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the…
- risk 0.00cvss 2.7epss 0.00
Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user…
- risk 0.00cvss 8.8epss 0.01
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test…
- risk 0.00cvss 4.3epss 0.00
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be…
- risk 0.00cvss 9.8epss 0.01
Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
- risk 0.00cvss 5.3epss 0.01
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.
- risk 0.00cvss 3.3epss 0.00
Missing Authorization in GitHub repository hamza417/inure prior to Build95.
- risk 0.00cvss 5.5epss 0.00
Missing Authorization in GitHub repository hamza417/inure prior to build94.
- risk 0.00cvss 5.5epss 0.00
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN…
- risk 0.00cvss 5.3epss 0.00
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
- risk 0.00cvss 6.1epss 0.00
Missing Authorization in GitHub repository hamza417/inure prior to build88.
- risk 0.00cvss 5.5epss 0.00
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
- risk 0.00cvss 5.9epss 0.00
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.
- risk 0.00cvss 8.1epss 0.01
Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request is made using an API key, the backend fails to verify the permission scopes associated with the key, effectively bypassing permission checks entirely for some…
- risk 0.00cvss 7.5epss 0.00
Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.
- risk 0.00cvss 5.4epss 0.01
Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a `missing access control` was found, which allows a User with the lowest privileges to leak all the tasks and projects titles within the software, even if they…
- risk 0.00cvss 5.4epss 0.00
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to a missing access control vulnerability that allows a user with low privileges to create or transfer tasks to any project within the software, even…
- risk 0.00cvss 5.4epss 0.00
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
- risk 0.00cvss 6.5epss 0.01
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabled in…
- risk 0.00cvss 3.1epss 0.01
Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server 6.1 and below, the UI which allows…