VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 461 of 463
  • CVE-2022-0756MedMar 7, 2022
    risk 0.00cvss 6.5epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2022-0755MedMar 7, 2022
    risk 0.00cvss 4.3epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2021-3656HigMar 4, 2022
    risk 0.00cvss 8.8epss 0.01

    A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue…

  • CVE-2022-0726MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-21707MedJan 21, 2022
    risk 0.00cvss 6.3epss 0.01

    wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…

  • CVE-2021-43847MedDec 20, 2021
    risk 0.00cvss 6.5epss 0.01

    HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.

  • CVE-2021-35413HigDec 3, 2021
    risk 0.00cvss 8.8epss 0.03

    A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.

  • CVE-2021-21687CriNov 4, 2021
    risk 0.00cvss 9.1epss 0.01

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.

  • CVE-2021-39225HigOct 25, 2021
    risk 0.00cvss 8.1epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9,…

  • CVE-2021-39184MedOct 12, 2021
    risk 0.00cvss 6.8epss 0.01

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The…

  • CVE-2021-38388HigSep 8, 2021
    risk 0.00cvss 8.8epss 0.01

    Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.

  • CVE-2021-38698MedSep 7, 2021
    risk 0.00cvss 6.5epss 0.02

    HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.

  • CVE-2021-32748MedJul 27, 2021
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP…

  • CVE-2021-21676MedJun 30, 2021
    risk 0.00cvss 4.3epss 0.01

    Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.

  • CVE-2021-21382HigJun 11, 2021
    risk 0.00cvss 8.6epss 0.01

    Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship…

  • CVE-2021-22896MedJun 11, 2021
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.

  • CVE-2021-21663MedJun 10, 2021
    risk 0.00cvss 4.3epss 0.01

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password…

  • CVE-2021-22877MedMar 3, 2021
    risk 0.00cvss 6.5epss 0.02

    A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.

  • CVE-2021-21255MedMar 2, 2021
    risk 0.00cvss 5.8epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.

  • CVE-2020-29160HigDec 28, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.