CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,735)
page 14 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-52538 | Cri | 0.59 | 9.1 | 0.00 | Apr 8, 2024 | Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-25170 | Cri | 0.59 | 9.1 | 0.01 | Feb 28, 2024 | An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header. | ||
| CVE-2017-9453 | Cri | 0.59 | 9.0 | 0.01 | Sep 5, 2023 | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. | ||
| CVE-2023-33468 | Cri | 0.59 | 9.1 | 0.01 | Aug 9, 2023 | KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly… | ||
| CVE-2023-31997 | Cri | 0.59 | 9.0 | 0.00 | Jul 1, 2023 | UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the… | ||
| CVE-2023-34218 | Cri | 0.59 | 9.1 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible | ||
| CVE-2023-23304 | Cri | 0.59 | 9.1 | 0.01 | May 23, 2023 | The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module… | ||
| CVE-2023-27578 | Cri | 0.59 | 9.1 | 0.01 | Mar 20, 2023 | Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages… | ||
| CVE-2023-22610 | Cri | 0.59 | 9.1 | 0.01 | Jan 31, 2023 | A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port. | ||
| CVE-2023-22482 | Cri | 0.59 | 9.0 | 0.01 | Jan 26, 2023 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers… | ||
| CVE-2022-45891 | Cri | 0.59 | 9.1 | 0.01 | Dec 25, 2022 | Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList). | ||
| CVE-2022-41923 | Cri | 0.59 | 9.1 | 0.02 | Nov 23, 2022 | Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework… | ||
| CVE-2022-31247 | Cri | 0.59 | 9.1 | 0.01 | Sep 7, 2022 | An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner… | ||
| CVE-2022-0670 | Cri | 0.59 | 9.1 | 0.01 | Jul 25, 2022 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise… | ||
| CVE-2022-26629 | Cri | 0.59 | 9.1 | 0.03 | Mar 24, 2022 | An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function. | ||
| CVE-2022-0482 | Cri | 0.59 | 9.1 | 0.44 | Mar 9, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | ||
| CVE-2021-39233 | Cri | 0.59 | 9.1 | 0.02 | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client. | ||
| CVE-2021-41244 | Cri | 0.59 | 9.1 | 0.03 | Nov 15, 2021 | Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.… | ||
| CVE-2021-30925 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2021 | The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences. | ||
| CVE-2021-30856 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2021 | This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences. |
- risk 0.59cvss 9.1epss 0.00
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.59cvss 9.1epss 0.01
An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
- risk 0.59cvss 9.0epss 0.01
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
- risk 0.59cvss 9.1epss 0.01
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly…
- risk 0.59cvss 9.0epss 0.00
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the…
- risk 0.59cvss 9.1epss 0.01
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
- risk 0.59cvss 9.1epss 0.01
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module…
- risk 0.59cvss 9.1epss 0.01
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages…
- risk 0.59cvss 9.1epss 0.01
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.
- risk 0.59cvss 9.0epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers…
- risk 0.59cvss 9.1epss 0.01
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
- risk 0.59cvss 9.1epss 0.02
Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework…
- risk 0.59cvss 9.1epss 0.01
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner…
- risk 0.59cvss 9.1epss 0.01
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise…
- risk 0.59cvss 9.1epss 0.03
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
- risk 0.59cvss 9.1epss 0.44
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- risk 0.59cvss 9.1epss 0.02
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.
- risk 0.59cvss 9.1epss 0.03
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.…
- risk 0.59cvss 9.1epss 0.01
The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.
- risk 0.59cvss 9.1epss 0.01
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences.