VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,365)

page 466 of 469
  • CVE-2022-23055Jun 22, 2022
    risk 0.00cvss epss 0.01

    In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker…

  • CVE-2022-30594HigMay 12, 2022
    risk 0.00cvss 7.8epss 0.01

    The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.

  • CVE-2022-21718LowMar 22, 2022
    risk 0.00cvss 3.4epss 0.01

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth…

  • CVE-2021-41233MedMar 10, 2022
    risk 0.00cvss 6.5epss 0.01

    Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful…

  • CVE-2021-41241MedMar 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted…

  • CVE-2021-41239MedMar 8, 2022
    risk 0.00cvss 5.3epss 0.01

    Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings…

  • CVE-2022-0756MedMar 7, 2022
    risk 0.00cvss 6.5epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2022-0755MedMar 7, 2022
    risk 0.00cvss 4.3epss 0.01

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2021-3656HigMar 4, 2022
    risk 0.00cvss 8.8epss 0.01

    A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue…

  • CVE-2022-0726MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-21707MedJan 21, 2022
    risk 0.00cvss 6.3epss 0.01

    wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…

  • CVE-2021-43847MedDec 20, 2021
    risk 0.00cvss 6.5epss 0.01

    HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.

  • CVE-2021-35413HigDec 3, 2021
    risk 0.00cvss 8.8epss 0.03

    A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.

  • CVE-2021-21687CriNov 4, 2021
    risk 0.00cvss 9.1epss 0.01

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.

  • CVE-2021-39225HigOct 25, 2021
    risk 0.00cvss 8.1epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9,…

  • CVE-2021-39184MedOct 12, 2021
    risk 0.00cvss 6.8epss 0.01

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The…

  • CVE-2021-38388HigSep 8, 2021
    risk 0.00cvss 8.8epss 0.01

    Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.

  • CVE-2021-38698MedSep 7, 2021
    risk 0.00cvss 6.5epss 0.02

    HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.

  • CVE-2021-32748MedJul 27, 2021
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP…

  • CVE-2021-21676MedJun 30, 2021
    risk 0.00cvss 4.3epss 0.01

    Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.