CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 114 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47090 | Med | 0.35 | 6.5 | 0.01 | Oct 30, 2023 | NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest… | ||
| CVE-2023-46125 | Med | 0.35 | 6.5 | 0.01 | Oct 25, 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows users to retrieve its configuration using the `GET… | ||
| CVE-2023-22067 | Med | 0.35 | 5.3 | 0.01 | Oct 17, 2023 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable… | ||
| CVE-2022-48538 | Med | 0.35 | 5.3 | 0.01 | Aug 22, 2023 | In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password. | ||
| CVE-2023-35908 | Med | 0.35 | 6.5 | 0.01 | Jul 12, 2023 | Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected | ||
| CVE-2023-3574 | Med | 0.35 | 6.5 | 0.01 | Jul 10, 2023 | Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. | ||
| CVE-2023-34197 | Med | 0.35 | 5.4 | 0.04 | Jul 7, 2023 | Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make… | ||
| CVE-2023-37300 | Med | 0.35 | 5.3 | 0.01 | Jun 30, 2023 | An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users. | ||
| CVE-2023-32061 | Med | 0.35 | 5.4 | 0.00 | Jun 13, 2023 | Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide… | ||
| CVE-2023-34965 | Med | 0.35 | 5.3 | 0.01 | Jun 13, 2023 | SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information. | ||
| CVE-2021-4352 | Med | 0.35 | 5.3 | 0.01 | Jun 7, 2023 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the… | ||
| CVE-2020-36710 | Med | 0.35 | 5.3 | 0.01 | Jun 7, 2023 | The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2. | ||
| CVE-2023-29240 | Med | 0.35 | 5.4 | 0.00 | May 3, 2023 | An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||
| CVE-2022-25091 | Med | 0.35 | 5.3 | 0.01 | Apr 27, 2023 | Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature. | ||
| CVE-2022-25274 | Med | 0.35 | 5.4 | 0.00 | Apr 26, 2023 | Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have… | ||
| CVE-2022-43770 | Med | 0.35 | 5.4 | 0.00 | Apr 11, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API. | ||
| CVE-2023-25924 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630. | ||
| CVE-2023-25768 | Med | 0.35 | 6.5 | 0.01 | Feb 15, 2023 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server. | ||
| CVE-2023-0298 | Med | 0.35 | 6.5 | 0.01 | Jan 14, 2023 | Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0. | ||
| CVE-2022-45956 | Med | 0.35 | 5.3 | 0.01 | Dec 12, 2022 | Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism. |
- risk 0.35cvss 6.5epss 0.01
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest…
- risk 0.35cvss 6.5epss 0.01
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows users to retrieve its configuration using the `GET…
- risk 0.35cvss 5.3epss 0.01
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable…
- risk 0.35cvss 5.3epss 0.01
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.
- risk 0.35cvss 6.5epss 0.01
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected
- risk 0.35cvss 6.5epss 0.01
Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.
- risk 0.35cvss 5.4epss 0.04
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make…
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.
- risk 0.35cvss 5.4epss 0.00
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide…
- risk 0.35cvss 5.3epss 0.01
SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.
- risk 0.35cvss 5.3epss 0.01
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the…
- risk 0.35cvss 5.3epss 0.01
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
- risk 0.35cvss 5.4epss 0.00
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- risk 0.35cvss 5.3epss 0.01
Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature.
- risk 0.35cvss 5.4epss 0.00
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have…
- risk 0.35cvss 5.4epss 0.00
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.
- risk 0.35cvss 5.4epss 0.00
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.
- risk 0.35cvss 6.5epss 0.01
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.
- risk 0.35cvss 6.5epss 0.01
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
- risk 0.35cvss 5.3epss 0.01
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.