CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,117)
page 504 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45307 | Hig | 0.00 | 8.8 | 0.00 | Sep 3, 2024 | SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of… | ||
| CVE-2024-45058 | Hig | 0.00 | 8.1 | 0.01 | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to change their user type to… | ||
| CVE-2024-44069 | Hig | 0.00 | 7.5 | 0.00 | Aug 19, 2024 | Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value… | ||
| CVE-2024-37903 | Hig | 0.00 | 8.2 | 0.01 | Jul 5, 2024 | Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining… | ||
| CVE-2024-36113 | Med | 0.00 | 4.9 | 0.00 | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users preventing them from logging in… | ||
| CVE-2024-37317 | Med | 0.00 | 4.6 | 0.00 | Jun 14, 2024 | The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the… | ||
| CVE-2024-37314 | Low | 0.00 | 3.5 | 0.00 | Jun 14, 2024 | Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2. | ||
| CVE-2024-4520 | Hig | 0.00 | 7.5 | 0.01 | Jun 4, 2024 | An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the… | ||
| CVE-2024-32466 | Low | 0.00 | 2.7 | 0.00 | Apr 18, 2024 | Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user… | ||
| CVE-2024-2216 | Hig | 0.00 | 8.8 | 0.01 | Mar 6, 2024 | A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test… | ||
| CVE-2024-21630 | Med | 0.00 | 4.3 | 0.00 | Jan 25, 2024 | Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be… | ||
| CVE-2023-50976 | Cri | 0.00 | 9.8 | 0.01 | Dec 18, 2023 | Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API. | ||
| CVE-2023-43194 | Med | 0.00 | 5.3 | 0.01 | Nov 2, 2023 | Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter. | ||
| CVE-2023-5862 | Low | 0.00 | 3.3 | 0.00 | Oct 31, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to Build95. | ||
| CVE-2023-5321 | Med | 0.00 | 5.5 | 0.00 | Sep 30, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to build94. | ||
| CVE-2023-4104 | Med | 0.00 | 5.5 | 0.00 | Sep 11, 2023 | An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN… | ||
| CVE-2023-41908 | Med | 0.00 | 5.3 | 0.00 | Sep 5, 2023 | Cerebrate before 1.15 lacks the Secure attribute for the session cookie. | ||
| CVE-2023-4434 | Med | 0.00 | 6.1 | 0.00 | Aug 20, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to build88. | ||
| CVE-2023-40216 | Med | 0.00 | 5.5 | 0.00 | Aug 10, 2023 | OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences. | ||
| CVE-2023-38494 | Med | 0.00 | 5.9 | 0.00 | Aug 4, 2023 | MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue. |
- risk 0.00cvss 8.8epss 0.00
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of…
- risk 0.00cvss 8.1epss 0.01
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to change their user type to…
- risk 0.00cvss 7.5epss 0.00
Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value…
- risk 0.00cvss 8.2epss 0.01
Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can extend the audience of a post they do not own to other Mastodon users on a target server, thus gaining…
- risk 0.00cvss 4.9epss 0.00
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users preventing them from logging in…
- risk 0.00cvss 4.6epss 0.00
The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the…
- risk 0.00cvss 3.5epss 0.00
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.
- risk 0.00cvss 7.5epss 0.01
An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the…
- risk 0.00cvss 2.7epss 0.00
Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user…
- risk 0.00cvss 8.8epss 0.01
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test…
- risk 0.00cvss 4.3epss 0.00
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be…
- risk 0.00cvss 9.8epss 0.01
Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
- risk 0.00cvss 5.3epss 0.01
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.
- risk 0.00cvss 3.3epss 0.00
Missing Authorization in GitHub repository hamza417/inure prior to Build95.
- risk 0.00cvss 5.5epss 0.00
Missing Authorization in GitHub repository hamza417/inure prior to build94.
- risk 0.00cvss 5.5epss 0.00
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN…
- risk 0.00cvss 5.3epss 0.00
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
- risk 0.00cvss 6.1epss 0.00
Missing Authorization in GitHub repository hamza417/inure prior to build88.
- risk 0.00cvss 5.5epss 0.00
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
- risk 0.00cvss 5.9epss 0.00
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.