CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,365)
page 466 of 469| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23055 | 0.00 | — | 0.01 | Jun 22, 2022 | In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker… | |||
| CVE-2022-30594 | Hig | 0.00 | 7.8 | 0.01 | May 12, 2022 | The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. | ||
| CVE-2022-21718 | Low | 0.00 | 3.4 | 0.01 | Mar 22, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth… | ||
| CVE-2021-41233 | Med | 0.00 | 6.5 | 0.01 | Mar 10, 2022 | Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful… | ||
| CVE-2021-41241 | Med | 0.00 | 4.3 | 0.01 | Mar 8, 2022 | Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted… | ||
| CVE-2021-41239 | Med | 0.00 | 5.3 | 0.01 | Mar 8, 2022 | Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings… | ||
| CVE-2022-0756 | Med | 0.00 | 6.5 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2022-0755 | Med | 0.00 | 4.3 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2021-3656 | Hig | 0.00 | 8.8 | 0.01 | Mar 4, 2022 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue… | ||
| CVE-2022-0726 | Med | 0.00 | 5.4 | 0.01 | Feb 23, 2022 | Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0. | ||
| CVE-2022-21707 | Med | 0.00 | 6.3 | 0.01 | Jan 21, 2022 | wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for… | ||
| CVE-2021-43847 | Med | 0.00 | 6.5 | 0.01 | Dec 20, 2021 | HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue. | ||
| CVE-2021-35413 | Hig | 0.00 | 8.8 | 0.03 | Dec 3, 2021 | A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file. | ||
| CVE-2021-21687 | Cri | 0.00 | 9.1 | 0.01 | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar. | ||
| CVE-2021-39225 | Hig | 0.00 | 8.1 | 0.01 | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9,… | ||
| CVE-2021-39184 | Med | 0.00 | 6.8 | 0.01 | Oct 12, 2021 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The… | ||
| CVE-2021-38388 | Hig | 0.00 | 8.8 | 0.01 | Sep 8, 2021 | Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project. | ||
| CVE-2021-38698 | Med | 0.00 | 6.5 | 0.02 | Sep 7, 2021 | HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2. | ||
| CVE-2021-32748 | Med | 0.00 | 4.3 | 0.01 | Jul 27, 2021 | Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP… | ||
| CVE-2021-21676 | Med | 0.00 | 4.3 | 0.01 | Jun 30, 2021 | Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address. |
- CVE-2022-23055Jun 22, 2022risk 0.00cvss —epss 0.01
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker…
- risk 0.00cvss 7.8epss 0.01
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
- risk 0.00cvss 3.4epss 0.01
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth…
- risk 0.00cvss 6.5epss 0.01
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful…
- risk 0.00cvss 4.3epss 0.01
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted…
- risk 0.00cvss 5.3epss 0.01
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings…
- risk 0.00cvss 6.5epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 4.3epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 8.8epss 0.01
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue…
- risk 0.00cvss 5.4epss 0.01
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
- risk 0.00cvss 6.3epss 0.01
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…
- risk 0.00cvss 6.5epss 0.01
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.
- risk 0.00cvss 8.8epss 0.03
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
- risk 0.00cvss 9.1epss 0.01
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.
- risk 0.00cvss 8.1epss 0.01
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9,…
- risk 0.00cvss 6.8epss 0.01
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The…
- risk 0.00cvss 8.8epss 0.01
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
- risk 0.00cvss 6.5epss 0.02
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
- risk 0.00cvss 4.3epss 0.01
Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP…
- risk 0.00cvss 4.3epss 0.01
Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.