VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 136 of 213
  • CVE-2021-27793MedAug 12, 2021
    risk 0.35cvss 5.3epss 0.01

    ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the…

  • CVE-2020-28397MedAug 10, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl.…

  • CVE-2021-28674MedJul 30, 2021
    risk 0.35cvss 5.4epss 0.01

    The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the…

  • CVE-2021-36758MedJul 16, 2021
    risk 0.35cvss 5.4epss 0.00

    1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have…

  • CVE-2021-24379MedJun 21, 2021
    risk 0.35cvss 5.3epss 0.01

    The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin…

  • CVE-2021-21664MedJun 10, 2021
    risk 0.35cvss 6.5epss 0.01

    An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password…

  • CVE-2021-30539MedJun 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2021-3469MedJun 3, 2021
    risk 0.35cvss 5.4epss 0.00

    Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate requests that have subject alternative…

  • CVE-2020-26555MedMay 24, 2021
    risk 0.35cvss 5.4epss 0.01

    Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

  • CVE-2021-20429MedMay 14, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force ID: 196334.

  • CVE-2021-31554MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically created MediaWiki user accounts, thus allowing nefarious users to remain unblocked.

  • CVE-2021-31552MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create…

  • CVE-2021-21643MedApr 21, 2021
    risk 0.35cvss 6.5epss 0.01

    Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.

  • CVE-2020-36287MedApr 9, 2021
    risk 0.35cvss 5.3epss 0.09

    The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions…

  • CVE-2020-36238MedApr 1, 2021
    risk 0.35cvss 5.3epss 0.02

    The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions…

  • CVE-2021-29642MedMar 30, 2021
    risk 0.35cvss 5.3epss 0.01

    GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of GitHub access tokens.

  • CVE-2021-21623MedMar 18, 2021
    risk 0.35cvss 6.5epss 0.01

    An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.

  • CVE-2021-26027MedMar 4, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.

  • CVE-2021-27225MedMar 1, 2021
    risk 0.35cvss 5.4epss 0.01

    In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.

  • CVE-2021-21318MedFeb 18, 2021
    risk 0.35cvss 5.4epss 0.01

    Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a vulnerability in which publishing an episode with strict access rules will overwrite the currently set series access. This allows…