VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 145 of 187
  • CVE-2021-39904MedNov 5, 2021
    risk 0.28cvss 4.3epss 0.01

    An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions…

  • CVE-2021-39902MedNov 4, 2021
    risk 0.28cvss 4.3epss 0.01

    Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.

  • CVE-2021-1854MedSep 8, 2021
    risk 0.28cvss 4.3epss 0.01

    A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .

  • CVE-2021-22247MedAug 25, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

  • CVE-2021-22251MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

  • CVE-2021-36383MedJul 12, 2021
    risk 0.28cvss 4.3epss 0.01

    Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as…

  • CVE-2021-29961MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    When styling and rendering an oversized `` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.

  • CVE-2021-29959MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling…

  • CVE-2021-30537MedJun 7, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.

  • CVE-2021-20306MedJun 1, 2021
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to…

  • CVE-2021-24281MedMay 14, 2021
    risk 0.28cvss 4.3epss 0.01

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.

  • CVE-2021-21228MedApr 30, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2021-24207MedApr 5, 2021
    risk 0.28cvss 4.3epss 0.01

    By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.

  • CVE-2021-22176MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

  • CVE-2021-28681MedMar 18, 2021
    risk 0.28cvss 5.3epss 0.01

    Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldn't allow the user to…

  • CVE-2021-20676MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) versions prior to Ver3.0, type D (DL8-D) versions prior to Ver3.0, and type E (DL8-E) versions prior to Ver3.0) allows remote authenticated attackers to bypass…

  • CVE-2021-20282MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20281MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-21186MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.

  • CVE-2021-22134MedMar 8, 2021
    risk 0.28cvss 4.3epss 0.01

    A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents…