VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 130 of 187
  • CVE-2023-35653MedOct 11, 2023
    risk 0.29cvss 4.4epss 0.00

    In TBD of TBD, there is a possible way to access location information due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2022-3248MedOct 5, 2023
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.

  • CVE-2022-22307MedJun 15, 2023
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753.

  • CVE-2023-24999MedMar 11, 2023
    risk 0.29cvss 4.4epss 0.01

    HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8,…

  • CVE-2022-31252MedOct 6, 2022
    risk 0.29cvss 4.4epss 0.00

    A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a…

  • CVE-2022-0762MedFeb 26, 2022
    risk 0.29cvss 5.5epss 0.01

    Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-21894MedJan 11, 2022
    risk 0.29cvss 4.4epss 0.07

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2021-20868MedJan 4, 2022
    risk 0.29cvss 4.5epss 0.00

    Incorrect authorization vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier,…

  • CVE-2021-30538MedJun 7, 2021
    risk 0.29cvss 4.3epss 0.16

    Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2021-21411MedMar 26, 2021
    risk 0.29cvss 5.5epss 0.01

    OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the GitLab provider stopped working in the v7.0.0 release. Regardless of the flag settings, authorization…

  • CVE-2019-5533MedOct 29, 2019
    risk 0.29cvss 4.3epss 0.18

    In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and last name, phone…

  • CVE-2018-10910MedJan 28, 2019
    risk 0.29cvss 4.5epss 0.00

    A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51…

  • CVE-2018-5520MedMay 2, 2018
    risk 0.29cvss 4.4epss 0.01

    On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file system resources.

  • CVE-2026-16044MedAug 17, 2026
    risk 0.28cvss 5.4epss 0.00

    Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .boardarchive file. Mattermost…

  • CVE-2026-74248MedAug 14, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.

  • CVE-2026-58431MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Public-only API token restriction is not enforced on team API routes

  • CVE-2026-63295MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails…

  • CVE-2026-18433MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due…

  • CVE-2026-8667MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata…

  • CVE-2026-68755MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    A bundle writer may create misleading release promotion information under specific conditions.