CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,259)
page 461 of 463| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0756 | Med | 0.00 | 6.5 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2022-0755 | Med | 0.00 | 4.3 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2021-3656 | Hig | 0.00 | 8.8 | 0.01 | Mar 4, 2022 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue… | ||
| CVE-2022-0726 | Med | 0.00 | 5.4 | 0.01 | Feb 23, 2022 | Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0. | ||
| CVE-2022-21707 | Med | 0.00 | 6.3 | 0.01 | Jan 21, 2022 | wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for… | ||
| CVE-2021-43847 | Med | 0.00 | 6.5 | 0.01 | Dec 20, 2021 | HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue. | ||
| CVE-2021-35413 | Hig | 0.00 | 8.8 | 0.03 | Dec 3, 2021 | A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file. | ||
| CVE-2021-21687 | Cri | 0.00 | 9.1 | 0.01 | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar. | ||
| CVE-2021-39225 | Hig | 0.00 | 8.1 | 0.01 | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9,… | ||
| CVE-2021-39184 | Med | 0.00 | 6.8 | 0.01 | Oct 12, 2021 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The… | ||
| CVE-2021-38388 | Hig | 0.00 | 8.8 | 0.01 | Sep 8, 2021 | Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project. | ||
| CVE-2021-38698 | Med | 0.00 | 6.5 | 0.02 | Sep 7, 2021 | HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2. | ||
| CVE-2021-32748 | Med | 0.00 | 4.3 | 0.01 | Jul 27, 2021 | Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP… | ||
| CVE-2021-21676 | Med | 0.00 | 4.3 | 0.01 | Jun 30, 2021 | Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address. | ||
| CVE-2021-21382 | Hig | 0.00 | 8.6 | 0.01 | Jun 11, 2021 | Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship… | ||
| CVE-2021-22896 | Med | 0.00 | 4.3 | 0.01 | Jun 11, 2021 | Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users. | ||
| CVE-2021-21663 | Med | 0.00 | 4.3 | 0.01 | Jun 10, 2021 | A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password… | ||
| CVE-2021-22877 | Med | 0.00 | 6.5 | 0.02 | Mar 3, 2021 | A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet. | ||
| CVE-2021-21255 | Med | 0.00 | 5.8 | 0.01 | Mar 2, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4. | ||
| CVE-2020-29160 | Hig | 0.00 | 7.5 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing. |
- risk 0.00cvss 6.5epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 4.3epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 8.8epss 0.01
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue…
- risk 0.00cvss 5.4epss 0.01
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
- risk 0.00cvss 6.3epss 0.01
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…
- risk 0.00cvss 6.5epss 0.01
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.
- risk 0.00cvss 8.8epss 0.03
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
- risk 0.00cvss 9.1epss 0.01
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.
- risk 0.00cvss 8.1epss 0.01
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9,…
- risk 0.00cvss 6.8epss 0.01
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The…
- risk 0.00cvss 8.8epss 0.01
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
- risk 0.00cvss 6.5epss 0.02
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
- risk 0.00cvss 4.3epss 0.01
Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP…
- risk 0.00cvss 4.3epss 0.01
Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.
- risk 0.00cvss 8.6epss 0.01
Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship…
- risk 0.00cvss 4.3epss 0.01
Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.
- risk 0.00cvss 4.3epss 0.01
A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password…
- risk 0.00cvss 6.5epss 0.02
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.
- risk 0.00cvss 5.8epss 0.01
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.