VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,365)

page 467 of 469
  • CVE-2021-21382HigJun 11, 2021
    risk 0.00cvss 8.6epss 0.01

    Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship…

  • CVE-2021-22896MedJun 11, 2021
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.

  • CVE-2021-21663MedJun 10, 2021
    risk 0.00cvss 4.3epss 0.01

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password…

  • CVE-2021-22877MedMar 3, 2021
    risk 0.00cvss 6.5epss 0.02

    A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.

  • CVE-2021-21255MedMar 2, 2021
    risk 0.00cvss 5.8epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.

  • CVE-2020-29160HigDec 28, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.

  • CVE-2020-29158MedDec 28, 2020
    risk 0.00cvss 4.3epss 0.01

    An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.

  • CVE-2020-27777MedDec 15, 2020
    risk 0.00cvss 6.7epss 0.00

    A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further…

  • CVE-2020-2323MedDec 3, 2020
    risk 0.00cvss 5.3epss 0.01

    Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.

  • CVE-2020-2322HigDec 3, 2020
    risk 0.00cvss 7.5epss 0.01

    Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

  • CVE-2020-26212HigNov 25, 2020
    risk 0.00cvss 7.7epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.3, any authenticated user has read-only permissions to…

  • CVE-2020-28036CriNov 2, 2020
    risk 0.00cvss 9.8epss 0.05

    wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

  • CVE-2020-27998CriOct 29, 2020
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.

  • CVE-2020-27664CriOct 22, 2020
    risk 0.00cvss 9.8epss 0.02

    admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.

  • CVE-2020-15251HigOct 13, 2020
    risk 0.00cvss 7.7epss 0.01

    In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is an ACL bypass vulnerability. This plugin is bundled with MirahezeBot-Plugins with versions from 9.0.0 and less than 9.0.2 affected.…

  • CVE-2020-14306HigSep 16, 2020
    risk 0.00cvss 8.8epss 0.01

    An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions through 1.1.3. This flaw allows an attacker with a basic level of access to the cluster to deploy a custom gateway/pod to any namespace, potentially gaining…

  • CVE-2020-24928MedAug 29, 2020
    risk 0.00cvss 5.3epss 0.01

    managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origins, which allows attackers to obtain sensitive Discord user information.

  • CVE-2020-2234MedAug 12, 2020
    risk 0.00cvss 6.5epss 0.01

    A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing…

  • CVE-2020-15102MedJul 21, 2020
    risk 0.00cvss 6.5epss 0.01

    In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.

  • CVE-2020-15780MedJul 15, 2020
    risk 0.00cvss 6.7epss 0.01

    An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.